* [OE-core][wrynose 00/40] Patch review
@ 2026-09-05 20:44 Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 01/40] apt: mark CVE-2011-3374 as fixed-version Yoann Congal
` (39 more replies)
0 siblings, 40 replies; 41+ messages in thread
From: Yoann Congal @ 2026-09-05 20:44 UTC (permalink / raw)
To: openembedded-core
Hello,
This is a series dedicated to unblock a number of patches on scarthgap.
Please review this set of changes for wrynose and have comments back by
end of day Tuesday, September 8.
Passed a-full on autobuilder:
https://autobuilder.yoctoproject.org/valkyrie/?#/builders/29/builds/4666
Some builds failed due to failed access to our infrastructure (Michael
Halstead is looking into it)
* "Compare AB workers and SANITY_TESTED_DISTROS" failed but succeeded in
a previous run (with no change related to this)
* qemuarm64-armhost retried in https://autobuilder.yoctoproject.org/valkyrie/?#/builders/8/builds/4608
* qemux86 retried in https://autobuilder.yoctoproject.org/valkyrie/?#/builders/30/builds/4563
* qemuarmv5 retried in https://autobuilder.yoctoproject.org/valkyrie/?#/builders/80/builds/4409
* oe-selftest-armhost: Bitbake Selftest failed but that particular
bitbake commit succeeded in https://autobuilder.yoctoproject.org/valkyrie/?#/builders/23/builds/4798
The following changes since commit 00c66f1d38a234f7738c2eb8fafa41b4f057a865:
pseudo: 1.9.10 -> 1.9.11 (2026-08-28 17:24:32 +0200)
are available in the Git repository at:
https://git.openembedded.org/openembedded-core-contrib stable/wrynose-nut
https://git.openembedded.org/openembedded-core-contrib/log/?h=stable/wrynose-nut
for you to fetch changes up to 31def396136be047e10c507a50264aad52ba6b0f:
scripts/install-buildtools: Update to 6.0.3 (2026-09-04 16:21:55 +0200)
----------------------------------------------------------------
Abhishek Bachiphale (1):
perl: fix CVE-2026-42496 and CVE-2026-42497
Darsh Kelaiya (4):
python3-git: fix CVE-2026-42284
python3-git: fix CVE-2026-42215
python3-git: fix CVE-2026-44243
python3-git: fix CVE-2026-44244
Deepak Rathore (2):
python3-cryptography: backport stray file install fix
qemu: guard RESOLVE_CACHED strace flag
Devansh Patel (1):
apt: mark CVE-2011-3374 as fixed-version
Esa Jaaskela (1):
volatile-binds: order systemd-timesyncd after /var/lib
Hetvi Thakar (2):
python3-idna: Fix CVE-2026-45409
libssh2: Fix CVE-2026-58051
Jaipaul Cheernam (3):
expat: set CVE_STATUS for CVE-2026-72522
util-linux: Fix CVE-2026-3184
python3: upgrade 3.14.6 -> 3.14.7
Jakub Szczudlo (Nokia) (2):
gnutls: fix for CVE-2026-42011
gnutls: fix CVE-2026-42010
Peter Marko (5):
alsa-lib: patch CVE-2026-56109
libevent: set status for CVE-2026-63380
go: upgrade 1.26.5 -> 1.26.6
util-linux: set status for CVE-2026-13595
go: upgrade 1.26.6 -> 1.26.7
Richard Purdie (2):
python3-mako: upgrade 1.3.10 -> 1.3.12
python3-click: upgrade 8.3.1 -> 8.3.3
Ross Burton (1):
libevent: upgrade 2.1.12 -> 2.1.13
Sowmya Sathram (1):
binutils: stable 2.46 branch updates
Tafil Avdyli (2):
python3: add missing pyc files to core
python3: fix stringold cache files
Tim Orling (9):
python3-babel: fix CVE_PRODUCT
python3-pycryptodome: fix CVE_PRODUCT
python3-dbusmock: fix CVE_PRODUCT
python3-wheel: fix CVE_PRODUCT
python3-click: fix CVE_PRODUCT
python3-attrs: fix CVE_PRODUCT
python3-numpy: fix CVE_PRODUCT
python3-pycryptodomex: fix CVE_PRODUCT
python3-git: fix CVE_PRODUCT
Vijay Anusuri (3):
libxfont2: Fix CVE-2026-56001
libxfont2: Fix CVE-2026-56002
libxfont2: Fix CVE-2026-56003
Yoann Congal (1):
scripts/install-buildtools: Update to 6.0.3
meta/recipes-core/expat/expat_2.7.5.bb | 3 +
meta/recipes-core/util-linux/util-linux.inc | 3 +
.../util-linux/util-linux/CVE-2026-3184.patch | 61 ++++++++
.../volatile-binds/volatile-binds.bb | 9 +-
meta/recipes-devtools/apt/apt_3.0.3.bb | 3 +
.../binutils/binutils-2.46.inc | 2 +-
.../go/{go-1.26.5.inc => go-1.26.7.inc} | 2 +-
...e_1.26.5.bb => go-binary-native_1.26.7.bb} | 6 +-
..._1.26.5.bb => go-cross-canadian_1.26.7.bb} | 0
...{go-cross_1.26.5.bb => go-cross_1.26.7.bb} | 0
...osssdk_1.26.5.bb => go-crosssdk_1.26.7.bb} | 0
...runtime_1.26.5.bb => go-runtime_1.26.7.bb} | 0
.../go/{go_1.26.5.bb => go_1.26.7.bb} | 0
.../perl/files/CVE-2026-42496.patch | 99 ++++++++++++
meta/recipes-devtools/perl/perl_5.42.0.bb | 1 +
.../python/python3-attrs_25.4.0.bb | 2 +
.../python/python3-babel_2.18.0.bb | 2 +
...-click_8.3.1.bb => python3-click_8.3.3.bb} | 4 +-
.../python/python3-cryptography.bb | 1 +
...lling-stray-files-into-site-packages.patch | 55 +++++++
.../python/python3-dbusmock_0.38.1.bb | 2 +
.../python3-git/CVE-2026-42215_p1.patch | 60 ++++++++
.../python3-git/CVE-2026-42215_p2.patch | 45 ++++++
.../python/python3-git/CVE-2026-42284.patch | 36 +++++
.../python3-git/CVE-2026-44243_p1.patch | 134 +++++++++++++++++
.../python3-git/CVE-2026-44243_p2.patch | 83 +++++++++++
.../python3-git/CVE-2026-44244_p1.patch | 102 +++++++++++++
.../python3-git/CVE-2026-44244_p2.patch | 28 ++++
.../python/python3-git_3.1.43.bb | 10 ++
.../python3-idna/CVE-2026-45409_p1.patch | 75 ++++++++++
.../python3-idna/CVE-2026-45409_p2.patch | 48 ++++++
.../python3-idna/CVE-2026-45409_p3.patch | 72 +++++++++
.../python/python3-idna_3.11.bb | 4 +
...-mako_1.3.10.bb => python3-mako_1.3.12.bb} | 2 +-
.../python/python3-numpy_2.4.3.bb | 2 +
.../python/python3-pycryptodome_3.23.0.bb | 1 +
.../python/python3-pycryptodomex_3.23.0.bb | 2 +
.../python/python3-wheel_0.46.3.bb | 2 +
...shebang-overflow-on-python-config.py.patch | 6 +-
...e-stdin-I-O-errors-same-way-as-maste.patch | 4 +-
...-use-prefix-value-from-build-configu.patch | 7 +-
...-qemu-wrapper-when-gathering-profile.patch | 9 +-
...est_sysconfig-for-posix_user-purelib.patch | 4 +-
.../0001-prefer-valid-entrypoints.patch | 2 +-
...g.py-use-platlibdir-also-for-purelib.patch | 4 +-
...le.py-correct-the-test-output-format.patch | 6 +-
.../python/python3/CVE-2026-11940.patch | 67 ---------
.../python/python3/CVE-2026-11972.patch | 61 --------
.../python/python3/makerace.patch | 6 +-
.../python/python3/python3-manifest.json | 11 +-
.../python/python3/valid-dists.patch | 2 +-
.../{python3_3.14.6.bb => python3_3.14.7.bb} | 7 +-
meta/recipes-devtools/qemu/qemu.inc | 1 +
...-if-RESOLVE_CACHED-flag-is-defined-b.patch | 38 +++++
.../xorg-lib/libxfont2/CVE-2026-56001.patch | 75 ++++++++++
.../xorg-lib/libxfont2/CVE-2026-56002.patch | 138 +++++++++++++++++
.../xorg-lib/libxfont2/CVE-2026-56003.patch | 114 ++++++++++++++
.../xorg-lib/libxfont2_2.0.7.bb | 5 +
.../alsa/alsa-lib/CVE-2026-56109.patch | 33 ++++
.../alsa/alsa-lib_1.2.15.3.bb | 1 +
.../gnutls/gnutls/CVE-2026-42010.patch | 41 +++++
.../gnutls/gnutls/CVE-2026-42011_p1.patch | 43 ++++++
.../gnutls/gnutls/CVE-2026-42011_p2.patch | 141 ++++++++++++++++++
meta/recipes-support/gnutls/gnutls_3.8.12.bb | 3 +
....c-patch-out-tests-that-require-a-wo.patch | 8 +-
...ncrease-default-timeval-tolerance-50.patch | 10 +-
...-monotonic_prc_fallback-as-retriable.patch | 11 +-
...ts-are-marked-failed-only-when-all-a.patch | 9 +-
.../libevent/Makefile-missing-test-dir.patch | 14 +-
...{libevent_2.1.12.bb => libevent_2.1.13.bb} | 4 +-
.../libssh2/libssh2/CVE-2026-58051.patch | 34 +++++
.../recipes-support/libssh2/libssh2_1.11.1.bb | 1 +
scripts/install-buildtools | 4 +-
73 files changed, 1679 insertions(+), 206 deletions(-)
create mode 100644 meta/recipes-core/util-linux/util-linux/CVE-2026-3184.patch
rename meta/recipes-devtools/go/{go-1.26.5.inc => go-1.26.7.inc} (90%)
rename meta/recipes-devtools/go/{go-binary-native_1.26.5.bb => go-binary-native_1.26.7.bb} (80%)
rename meta/recipes-devtools/go/{go-cross-canadian_1.26.5.bb => go-cross-canadian_1.26.7.bb} (100%)
rename meta/recipes-devtools/go/{go-cross_1.26.5.bb => go-cross_1.26.7.bb} (100%)
rename meta/recipes-devtools/go/{go-crosssdk_1.26.5.bb => go-crosssdk_1.26.7.bb} (100%)
rename meta/recipes-devtools/go/{go-runtime_1.26.5.bb => go-runtime_1.26.7.bb} (100%)
rename meta/recipes-devtools/go/{go_1.26.5.bb => go_1.26.7.bb} (100%)
create mode 100644 meta/recipes-devtools/perl/files/CVE-2026-42496.patch
rename meta/recipes-devtools/python/{python3-click_8.3.1.bb => python3-click_8.3.3.bb} (87%)
create mode 100644 meta/recipes-devtools/python/python3-cryptography/0002-Fix-installing-stray-files-into-site-packages.patch
create mode 100644 meta/recipes-devtools/python/python3-git/CVE-2026-42215_p1.patch
create mode 100644 meta/recipes-devtools/python/python3-git/CVE-2026-42215_p2.patch
create mode 100644 meta/recipes-devtools/python/python3-git/CVE-2026-42284.patch
create mode 100644 meta/recipes-devtools/python/python3-git/CVE-2026-44243_p1.patch
create mode 100644 meta/recipes-devtools/python/python3-git/CVE-2026-44243_p2.patch
create mode 100644 meta/recipes-devtools/python/python3-git/CVE-2026-44244_p1.patch
create mode 100644 meta/recipes-devtools/python/python3-git/CVE-2026-44244_p2.patch
create mode 100644 meta/recipes-devtools/python/python3-idna/CVE-2026-45409_p1.patch
create mode 100644 meta/recipes-devtools/python/python3-idna/CVE-2026-45409_p2.patch
create mode 100644 meta/recipes-devtools/python/python3-idna/CVE-2026-45409_p3.patch
rename meta/recipes-devtools/python/{python3-mako_1.3.10.bb => python3-mako_1.3.12.bb} (88%)
delete mode 100644 meta/recipes-devtools/python/python3/CVE-2026-11940.patch
delete mode 100644 meta/recipes-devtools/python/python3/CVE-2026-11972.patch
rename meta/recipes-devtools/python/{python3_3.14.6.bb => python3_3.14.7.bb} (98%)
create mode 100644 meta/recipes-devtools/qemu/qemu/0012-linux-user-Check-if-RESOLVE_CACHED-flag-is-defined-b.patch
create mode 100644 meta/recipes-graphics/xorg-lib/libxfont2/CVE-2026-56001.patch
create mode 100644 meta/recipes-graphics/xorg-lib/libxfont2/CVE-2026-56002.patch
create mode 100644 meta/recipes-graphics/xorg-lib/libxfont2/CVE-2026-56003.patch
create mode 100644 meta/recipes-multimedia/alsa/alsa-lib/CVE-2026-56109.patch
create mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2026-42010.patch
create mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2026-42011_p1.patch
create mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2026-42011_p2.patch
rename meta/recipes-support/libevent/{libevent_2.1.12.bb => libevent_2.1.13.bb} (92%)
create mode 100644 meta/recipes-support/libssh2/libssh2/CVE-2026-58051.patch
^ permalink raw reply [flat|nested] 41+ messages in thread
* [OE-core][wrynose 01/40] apt: mark CVE-2011-3374 as fixed-version
2026-09-05 20:44 [OE-core][wrynose 00/40] Patch review Yoann Congal
@ 2026-09-05 20:44 ` Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 02/40] expat: set CVE_STATUS for CVE-2026-72522 Yoann Congal
` (38 subsequent siblings)
39 siblings, 0 replies; 41+ messages in thread
From: Yoann Congal @ 2026-09-05 20:44 UTC (permalink / raw)
To: openembedded-core
From: Devansh Patel <devanshp@cisco.com>
CVE-2011-3374 affects the legacy apt-key net-update command [1].
Upstream removed apt-key in apt 2.9.19 [2]. OE-Core uses apt 3.0.3,
so the vulnerable code is no longer present and cannot be restored by
configuration.
Mark the CVE as fixed-version.
[1] https://security-tracker.debian.org/tracker/CVE-2011-3374
[2] https://salsa.debian.org/apt-team/apt/-/commit/a00fbbdb2
Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit 5126e4792ddd8e6c721c47733d287633c234f2a9)
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
meta/recipes-devtools/apt/apt_3.0.3.bb | 3 +++
1 file changed, 3 insertions(+)
diff --git a/meta/recipes-devtools/apt/apt_3.0.3.bb b/meta/recipes-devtools/apt/apt_3.0.3.bb
index 08b6bac2e4f..7c72f489a3f 100644
--- a/meta/recipes-devtools/apt/apt_3.0.3.bb
+++ b/meta/recipes-devtools/apt/apt_3.0.3.bb
@@ -34,6 +34,9 @@ UPSTREAM_CHECK_URI = "${DEBIAN_MIRROR}/main/a/apt/"
# to express 'divisible by 4 plus 2' in regex (that I know of), let's hardcode a few.
UPSTREAM_CHECK_REGEX = "[^\d\.](?P<pver>((2\.2)|(2\.6)|(3\.0)|(3\.4)|(3\.8)|(4\.2))(\.\d+)+)\.tar"
+# apt-key, including the vulnerable net-update path, was removed in 2.9.19.
+CVE_STATUS[CVE-2011-3374] = "fixed-version: apt-key was removed in 2.9.19"
+
inherit cmake perlnative bash-completion useradd
# User is added to allow apt to drop privs, will runtime warn without
^ permalink raw reply related [flat|nested] 41+ messages in thread
* [OE-core][wrynose 02/40] expat: set CVE_STATUS for CVE-2026-72522
2026-09-05 20:44 [OE-core][wrynose 00/40] Patch review Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 01/40] apt: mark CVE-2011-3374 as fixed-version Yoann Congal
@ 2026-09-05 20:44 ` Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 03/40] python3-git: fix CVE-2026-42284 Yoann Congal
` (37 subsequent siblings)
39 siblings, 0 replies; 41+ messages in thread
From: Yoann Congal @ 2026-09-05 20:44 UTC (permalink / raw)
To: openembedded-core
From: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
CVE-2026-72522 is an out-of-bounds read and infinite loop vulnerability in
Expat's *_toUtf16 functions caused by mis-classifying low surrogates as
high surrogates.
Our Yocto configuration is not affected by this vulnerability:
- Expat is compiled with EXPAT_CHAR_TYPE=char (8-bit character representation).
- Neither XML_UNICODE nor XML_UNICODE_WCHAR_T is defined.
- The vulnerable *_toUtf16 functions are only invoked when Expat's internal
character type is 16-bit (ushort or wchar_t).
- In 8-bit mode, Expat handles conversion using *_toUtf8 functions even when
parsing UTF-16 encoded XML inputs, rendering the vulnerable code path
unreachable.
Reference:
[1] https://nvd.nist.gov/vuln/detail/CVE-2026-72522
[2] https://github.com/libexpat/libexpat/pull/1296/changes/8fbfb52fa88e040e8b0b7a9d39f260d6a9e8b6db
Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
[YC: EXPAT_CHAR_TYPE=char is the default and we do not change it]
---
meta/recipes-core/expat/expat_2.7.5.bb | 3 +++
1 file changed, 3 insertions(+)
diff --git a/meta/recipes-core/expat/expat_2.7.5.bb b/meta/recipes-core/expat/expat_2.7.5.bb
index 890ee5b7d34..da35b8f9ff5 100644
--- a/meta/recipes-core/expat/expat_2.7.5.bb
+++ b/meta/recipes-core/expat/expat_2.7.5.bb
@@ -57,3 +57,6 @@ do_install_ptest:class-target() {
BBCLASSEXTEND += "native nativesdk"
CVE_PRODUCT = "expat libexpat"
+
+CVE_STATUS[CVE-2026-72522] = "not-applicable-config: Needs Expat compiled with 16bit character support , Issue only affects firefox/Windows. \
+EXPAT_CHAR_TYPE:STRING=char is for Yocto builds"
^ permalink raw reply related [flat|nested] 41+ messages in thread
* [OE-core][wrynose 03/40] python3-git: fix CVE-2026-42284
2026-09-05 20:44 [OE-core][wrynose 00/40] Patch review Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 01/40] apt: mark CVE-2011-3374 as fixed-version Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 02/40] expat: set CVE_STATUS for CVE-2026-72522 Yoann Congal
@ 2026-09-05 20:44 ` Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 04/40] python3-git: fix CVE-2026-42215 Yoann Congal
` (36 subsequent siblings)
39 siblings, 0 replies; 41+ messages in thread
From: Yoann Congal @ 2026-09-05 20:44 UTC (permalink / raw)
To: openembedded-core
From: Darsh Kelaiya <dkelaiya@cisco.com>
This patch applies the upstream fix as referenced in [2], using the
commit shown in [1].
[1] https://github.com/gitpython-developers/GitPython/commit/c9a26789d88b18f8b4620f37307df2976292d2a0
[2] https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-x2qx-6953-8485
Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
[YC:
See https://github.com/gitpython-developers/GitPython/pull/2130#issue-4299717224:
The author links the fix to this advisory/CVE.
]
---
.../python/python3-git/CVE-2026-42284.patch | 36 +++++++++++++++++++
.../python/python3-git_3.1.43.bb | 2 ++
2 files changed, 38 insertions(+)
create mode 100644 meta/recipes-devtools/python/python3-git/CVE-2026-42284.patch
diff --git a/meta/recipes-devtools/python/python3-git/CVE-2026-42284.patch b/meta/recipes-devtools/python/python3-git/CVE-2026-42284.patch
new file mode 100644
index 00000000000..3e5b9908a78
--- /dev/null
+++ b/meta/recipes-devtools/python/python3-git/CVE-2026-42284.patch
@@ -0,0 +1,36 @@
+From 01d579e1b0a3e78cf82695b84967d0c343cfdd0f Mon Sep 17 00:00:00 2001
+From: "GPT 5.4" <codex@openai.com>
+Date: Tue, 21 Apr 2026 09:30:29 +0800
+Subject: [PATCH] Make sure that multi-options are checked after splitting them
+ with `shlex`
+
+CVE: CVE-2026-42284
+Upstream-Status: Backport [https://github.com/gitpython-developers/GitPython/commit/c9a26789d88b18f8b4620f37307df2976292d2a0]
+
+Backport Changes:
+- Omitted test/test_clone.py and test/test_submodule.py because the
+ PyPI 3.1.43 source used by the recipe does not ship the upstream
+ test tree.
+
+Co-authored-by: Sebastian Thiel <sebastian.thiel@icloud.com>
+(cherry picked from commit c9a26789d88b18f8b4620f37307df2976292d2a0)
+Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
+---
+ git/repo/base.py | 4 ++--
+ 1 file changed, 2 insertions(+), 2 deletions(-)
+
+diff --git a/git/repo/base.py b/git/repo/base.py
+index 51ea7690..8059fceb 100644
+--- a/git/repo/base.py
++++ b/git/repo/base.py
+@@ -1365,8 +1365,8 @@ class Repo:
+ Git.check_unsafe_protocols(str(url))
+ if not allow_unsafe_options:
+ Git.check_unsafe_options(options=list(kwargs.keys()), unsafe_options=cls.unsafe_git_clone_options)
+- if not allow_unsafe_options and multi_options:
+- Git.check_unsafe_options(options=multi_options, unsafe_options=cls.unsafe_git_clone_options)
++ if not allow_unsafe_options and multi:
++ Git.check_unsafe_options(options=multi, unsafe_options=cls.unsafe_git_clone_options)
+
+ proc = git.clone(
+ multi,
diff --git a/meta/recipes-devtools/python/python3-git_3.1.43.bb b/meta/recipes-devtools/python/python3-git_3.1.43.bb
index 45c988117bd..bfbdd802893 100644
--- a/meta/recipes-devtools/python/python3-git_3.1.43.bb
+++ b/meta/recipes-devtools/python/python3-git_3.1.43.bb
@@ -12,6 +12,8 @@ PYPI_PACKAGE = "GitPython"
inherit pypi python_setuptools_build_meta
+SRC_URI += "file://CVE-2026-42284.patch \
+ "
SRC_URI[sha256sum] = "35f314a9f878467f5453cc1fee295c3e18e52f1b99f10f6cf5b1682e968a9e7c"
DEPENDS += " python3-gitdb"
^ permalink raw reply related [flat|nested] 41+ messages in thread
* [OE-core][wrynose 04/40] python3-git: fix CVE-2026-42215
2026-09-05 20:44 [OE-core][wrynose 00/40] Patch review Yoann Congal
` (2 preceding siblings ...)
2026-09-05 20:44 ` [OE-core][wrynose 03/40] python3-git: fix CVE-2026-42284 Yoann Congal
@ 2026-09-05 20:44 ` Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 05/40] python3-git: fix CVE-2026-44243 Yoann Congal
` (35 subsequent siblings)
39 siblings, 0 replies; 41+ messages in thread
From: Yoann Congal @ 2026-09-05 20:44 UTC (permalink / raw)
To: openembedded-core
From: Darsh Kelaiya <dkelaiya@cisco.com>
This patch applies the upstream fix as referenced in [3],
using the backported commits shown in [1] and [2].
[1] https://github.com/gitpython-developers/GitPython/commit/142195888e713542189533a52cdfc333f05c3af6
[2] https://github.com/gitpython-developers/GitPython/commit/43d92dec4683568d11495956dd556161f17c3ea8
[3] https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-rpm5-65cw-6hj4
Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../python3-git/CVE-2026-42215_p1.patch | 60 +++++++++++++++++++
.../python3-git/CVE-2026-42215_p2.patch | 45 ++++++++++++++
.../python/python3-git_3.1.43.bb | 2 +
3 files changed, 107 insertions(+)
create mode 100644 meta/recipes-devtools/python/python3-git/CVE-2026-42215_p1.patch
create mode 100644 meta/recipes-devtools/python/python3-git/CVE-2026-42215_p2.patch
diff --git a/meta/recipes-devtools/python/python3-git/CVE-2026-42215_p1.patch b/meta/recipes-devtools/python/python3-git/CVE-2026-42215_p1.patch
new file mode 100644
index 00000000000..0129250fdfc
--- /dev/null
+++ b/meta/recipes-devtools/python/python3-git/CVE-2026-42215_p1.patch
@@ -0,0 +1,60 @@
+From dd5d1c4ddcc5d44faf4e71bcfa338f09db2022d6 Mon Sep 17 00:00:00 2001
+From: w <w@mac.lan>
+Date: Mon, 20 Apr 2026 23:29:50 -0400
+Subject: [PATCH] Block unsafe underscored git kwargs / Fix for
+ GHSA-rpm5-65cw-6hj4
+
+CVE: CVE-2026-42215
+Upstream-Status: Backport [https://github.com/gitpython-developers/GitPython/commit/142195888e713542189533a52cdfc333f05c3af6]
+
+Backport Changes:
+- Omitted test/test_clone.py, test/test_git.py, and
+ test/test_remote.py because the PyPI 3.1.43 source used by the
+ recipe does not ship the upstream test tree.
+
+(cherry picked from commit 142195888e713542189533a52cdfc333f05c3af6)
+Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
+---
+ git/cmd.py | 21 +++++++++++++--------
+ 1 file changed, 13 insertions(+), 8 deletions(-)
+
+diff --git a/git/cmd.py b/git/cmd.py
+index 90fc39cd..2ecb8e66 100644
+--- a/git/cmd.py
++++ b/git/cmd.py
+@@ -711,6 +711,12 @@ class Git(metaclass=_GitMeta):
+ f"The `{protocol}::` protocol looks suspicious, use `allow_unsafe_protocols=True` to allow it."
+ )
+
++ @classmethod
++ def _canonicalize_option_name(cls, option: str) -> str:
++ """Normalize an option or kwarg name for unsafe-option checks."""
++ option_name = option.lstrip("-").split("=", 1)[0].split(None, 1)[0]
++ return dashify(option_name)
++
+ @classmethod
+ def check_unsafe_options(cls, options: List[str], unsafe_options: List[str]) -> None:
+ """Check for unsafe options.
+@@ -718,15 +724,14 @@ class Git(metaclass=_GitMeta):
+ Some options that are passed to ``git <command>`` can be used to execute
+ arbitrary commands. These are blocked by default.
+ """
+- # Options can be of the form `foo`, `--foo bar`, or `--foo=bar`, so we need to
+- # check if they start with "--foo" or if they are equal to "foo".
+- bare_unsafe_options = [option.lstrip("-") for option in unsafe_options]
++ # Options can be of the form `foo`, `--foo`, `--foo bar`, or `--foo=bar`.
++ canonical_unsafe_options = {cls._canonicalize_option_name(option): option for option in unsafe_options}
+ for option in options:
+- for unsafe_option, bare_option in zip(unsafe_options, bare_unsafe_options):
+- if option.startswith(unsafe_option) or option == bare_option:
+- raise UnsafeOptionError(
+- f"{unsafe_option} is not allowed, use `allow_unsafe_options=True` to allow it."
+- )
++ unsafe_option = canonical_unsafe_options.get(cls._canonicalize_option_name(option))
++ if unsafe_option is not None:
++ raise UnsafeOptionError(
++ f"{unsafe_option} is not allowed, use `allow_unsafe_options=True` to allow it."
++ )
+
+ class AutoInterrupt:
+ """Process wrapper that terminates the wrapped process on finalization.
diff --git a/meta/recipes-devtools/python/python3-git/CVE-2026-42215_p2.patch b/meta/recipes-devtools/python/python3-git/CVE-2026-42215_p2.patch
new file mode 100644
index 00000000000..a23fba8d819
--- /dev/null
+++ b/meta/recipes-devtools/python/python3-git/CVE-2026-42215_p2.patch
@@ -0,0 +1,45 @@
+From 3ee4db90229dbb1fbdc8572dc8219990d70db368 Mon Sep 17 00:00:00 2001
+From: w <w@mac.lan>
+Date: Tue, 21 Apr 2026 12:03:20 -0400
+Subject: [PATCH] git.cmd: harden unsafe option canonicalization and isolate
+ push test cases
+
+CVE: CVE-2026-42215
+Upstream-Status: Backport [https://github.com/gitpython-developers/GitPython/commit/43d92dec4683568d11495956dd556161f17c3ea8]
+
+Backport Changes:
+- Omitted test/test_remote.py because the PyPI 3.1.43 source used
+ by the recipe does not ship the upstream test tree.
+
+(cherry picked from commit 43d92dec4683568d11495956dd556161f17c3ea8)
+Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
+---
+ git/cmd.py | 15 ++++++++++++---
+ 1 file changed, 12 insertions(+), 3 deletions(-)
+
+diff --git a/git/cmd.py b/git/cmd.py
+index 372eac28..a1e77bdb 100644
+--- a/git/cmd.py
++++ b/git/cmd.py
+@@ -713,9 +713,18 @@ class Git(metaclass=_GitMeta):
+
+ @classmethod
+ def _canonicalize_option_name(cls, option: str) -> str:
+- """Normalize an option or kwarg name for unsafe-option checks."""
+- option_name = option.lstrip("-").split("=", 1)[0].split(None, 1)[0]
+- return dashify(option_name)
++ """Return the option name used for unsafe-option checks.
++
++ Examples:
++ ``"--upload-pack=/tmp/helper"`` -> ``"upload-pack"``
++ ``"upload_pack"`` -> ``"upload-pack"``
++ ``"--config core.filemode=false"`` -> ``"config"``
++ """
++ option_name = option.lstrip("-").split("=", 1)[0]
++ option_tokens = option_name.split(None, 1)
++ if not option_tokens:
++ return ""
++ return dashify(option_tokens[0])
+
+ @classmethod
+ def check_unsafe_options(cls, options: List[str], unsafe_options: List[str]) -> None:
diff --git a/meta/recipes-devtools/python/python3-git_3.1.43.bb b/meta/recipes-devtools/python/python3-git_3.1.43.bb
index bfbdd802893..26d9a3f0633 100644
--- a/meta/recipes-devtools/python/python3-git_3.1.43.bb
+++ b/meta/recipes-devtools/python/python3-git_3.1.43.bb
@@ -13,6 +13,8 @@ PYPI_PACKAGE = "GitPython"
inherit pypi python_setuptools_build_meta
SRC_URI += "file://CVE-2026-42284.patch \
+ file://CVE-2026-42215_p1.patch \
+ file://CVE-2026-42215_p2.patch \
"
SRC_URI[sha256sum] = "35f314a9f878467f5453cc1fee295c3e18e52f1b99f10f6cf5b1682e968a9e7c"
^ permalink raw reply related [flat|nested] 41+ messages in thread
* [OE-core][wrynose 05/40] python3-git: fix CVE-2026-44243
2026-09-05 20:44 [OE-core][wrynose 00/40] Patch review Yoann Congal
` (3 preceding siblings ...)
2026-09-05 20:44 ` [OE-core][wrynose 04/40] python3-git: fix CVE-2026-42215 Yoann Congal
@ 2026-09-05 20:44 ` Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 06/40] python3-git: fix CVE-2026-44244 Yoann Congal
` (34 subsequent siblings)
39 siblings, 0 replies; 41+ messages in thread
From: Yoann Congal @ 2026-09-05 20:44 UTC (permalink / raw)
To: openembedded-core
From: Darsh Kelaiya <dkelaiya@cisco.com>
This patch applies the upstream fix as referenced in [3], using all the
backported commits shown in [1] and [2].
[1] https://github.com/gitpython-developers/GitPython/commit/25ba54dd3fb374b8fade7de4be1ac2ac84722190
[2] https://github.com/gitpython-developers/GitPython/commit/4af8463cca31c2369312fcaa5309dfc30756c7b6
[3] https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7545-fcxq-7j24
Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../python3-git/CVE-2026-44243_p1.patch | 134 ++++++++++++++++++
.../python3-git/CVE-2026-44243_p2.patch | 83 +++++++++++
.../python/python3-git_3.1.43.bb | 2 +
3 files changed, 219 insertions(+)
create mode 100644 meta/recipes-devtools/python/python3-git/CVE-2026-44243_p1.patch
create mode 100644 meta/recipes-devtools/python/python3-git/CVE-2026-44243_p2.patch
diff --git a/meta/recipes-devtools/python/python3-git/CVE-2026-44243_p1.patch b/meta/recipes-devtools/python/python3-git/CVE-2026-44243_p1.patch
new file mode 100644
index 00000000000..7eaaf703db4
--- /dev/null
+++ b/meta/recipes-devtools/python/python3-git/CVE-2026-44243_p1.patch
@@ -0,0 +1,134 @@
+From 84b84e90d1ce0b35d627bee6c65f3218c72a53f5 Mon Sep 17 00:00:00 2001
+From: "GPT 5.5" <codex@openai.com>
+Date: Tue, 28 Apr 2026 09:17:31 +0800
+Subject: [PATCH] prevent out-of-repo access when manipulating references.
+
+This previously made it possible to create, modify and delete files outside outside
+of the repository, which is a problem if inputs aren't trusted.
+
+CVE: CVE-2026-44243
+Upstream-Status: Backport [https://github.com/gitpython-developers/GitPython/commit/25ba54dd3fb374b8fade7de4be1ac2ac84722190]
+
+Backport Changes:
+- Omitted test/test_refs.py because the PyPI 3.1.43 source used by
+ the recipe does not ship the upstream test tree.
+
+Co-authored-by: Sebastian Thiel <sebastian.thiel@icloud.com>
+(cherry picked from commit 25ba54dd3fb374b8fade7de4be1ac2ac84722190)
+Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
+---
+ git/refs/log.py | 2 +-
+ git/refs/remote.py | 5 +++--
+ git/refs/symbolic.py | 37 +++++++++++++++++++++++++++++++------
+ 3 files changed, 35 insertions(+), 9 deletions(-)
+
+diff --git a/git/refs/log.py b/git/refs/log.py
+index 17e3a94b..88906758 100644
+--- a/git/refs/log.py
++++ b/git/refs/log.py
+@@ -213,7 +213,7 @@ class RefLog(List[RefLogEntry], Serializable):
+ :param ref:
+ :class:`~git.refs.symbolic.SymbolicReference` instance
+ """
+- return osp.join(ref.repo.git_dir, "logs", to_native_path(ref.path))
++ return to_native_path(ref._get_validated_reflog_path(ref.repo, ref.path))
+
+ @classmethod
+ def iter_entries(cls, stream: Union[str, "BytesIO", mmap]) -> Iterator[RefLogEntry]:
+diff --git a/git/refs/remote.py b/git/refs/remote.py
+index b4f4f7b3..8244470b 100644
+--- a/git/refs/remote.py
++++ b/git/refs/remote.py
+@@ -63,12 +63,13 @@ class RemoteReference(Head):
+ # generally ignored in the refs/ folder. We don't though and delete remainders
+ # manually.
+ for ref in refs:
++ cls._check_ref_name_valid(ref.path)
+ try:
+- os.remove(os.path.join(repo.common_dir, ref.path))
++ os.remove(cls._get_validated_path(repo.common_dir, ref.path))
+ except OSError:
+ pass
+ try:
+- os.remove(os.path.join(repo.git_dir, ref.path))
++ os.remove(cls._get_validated_path(repo.git_dir, ref.path))
+ except OSError:
+ pass
+ # END for each ref
+diff --git a/git/refs/symbolic.py b/git/refs/symbolic.py
+index 510850b2..ba24f2c2 100644
+--- a/git/refs/symbolic.py
++++ b/git/refs/symbolic.py
+@@ -109,6 +109,32 @@ class SymbolicReference:
+ def abspath(self) -> PathLike:
+ return join_path_native(_git_dir(self.repo, self.path), self.path)
+
++ @staticmethod
++ def _get_validated_path(base: PathLike, path: PathLike) -> str:
++ path = os.fspath(path)
++ base_path = os.path.realpath(os.fspath(base))
++ abs_path = os.path.realpath(os.path.join(base_path, path))
++ try:
++ common_path = os.path.commonpath([base_path, abs_path])
++ except ValueError as e:
++ raise ValueError("Reference path %r escapes the repository" % path) from e
++ if os.path.normcase(common_path) != os.path.normcase(base_path):
++ raise ValueError("Reference path %r escapes the repository" % path)
++ return abs_path
++
++ @classmethod
++ def _get_validated_ref_path(cls, repo: "Repo", path: PathLike) -> str:
++ """Return the absolute filesystem path for a ref after validating it."""
++ cls._check_ref_name_valid(path)
++ ref_path = os.fspath(path)
++ return cls._get_validated_path(_git_dir(repo, ref_path), ref_path)
++
++ @classmethod
++ def _get_validated_reflog_path(cls, repo: "Repo", path: PathLike) -> str:
++ """Return the absolute filesystem path for a reflog after validating it."""
++ cls._check_ref_name_valid(path)
++ return cls._get_validated_path(os.path.join(repo.git_dir, "logs"), path)
++
+ @classmethod
+ def _get_packed_refs_path(cls, repo: "Repo") -> str:
+ return os.path.join(repo.common_dir, "packed-refs")
+@@ -478,7 +504,7 @@ class SymbolicReference:
+ # END handle non-existing
+ # END retrieve old hexsha
+
+- fpath = self.abspath
++ fpath = self._get_validated_ref_path(self.repo, self.path)
+ assure_directory_exists(fpath, is_file=True)
+
+ lfd = LockedFD(fpath)
+@@ -623,7 +649,7 @@ class SymbolicReference:
+ Alternatively the symbolic reference to be deleted.
+ """
+ full_ref_path = cls.to_full_path(path)
+- abs_path = os.path.join(repo.common_dir, full_ref_path)
++ abs_path = cls._get_validated_ref_path(repo, full_ref_path)
+ if os.path.exists(abs_path):
+ os.remove(abs_path)
+ else:
+@@ -686,9 +712,8 @@ class SymbolicReference:
+ symbolic reference. Otherwise it will be resolved to the corresponding object
+ and a detached symbolic reference will be created instead.
+ """
+- git_dir = _git_dir(repo, path)
+ full_ref_path = cls.to_full_path(path)
+- abs_ref_path = os.path.join(git_dir, full_ref_path)
++ abs_ref_path = cls._get_validated_ref_path(repo, full_ref_path)
+
+ # Figure out target data.
+ target = reference
+@@ -780,8 +805,8 @@ class SymbolicReference:
+ if self.path == new_path:
+ return self
+
+- new_abs_path = os.path.join(_git_dir(self.repo, new_path), new_path)
+- cur_abs_path = os.path.join(_git_dir(self.repo, self.path), self.path)
++ new_abs_path = self._get_validated_ref_path(self.repo, new_path)
++ cur_abs_path = self._get_validated_ref_path(self.repo, self.path)
+ if os.path.isfile(new_abs_path):
+ if not force:
+ # If they point to the same file, it's not an error.
diff --git a/meta/recipes-devtools/python/python3-git/CVE-2026-44243_p2.patch b/meta/recipes-devtools/python/python3-git/CVE-2026-44243_p2.patch
new file mode 100644
index 00000000000..04e83d36574
--- /dev/null
+++ b/meta/recipes-devtools/python/python3-git/CVE-2026-44243_p2.patch
@@ -0,0 +1,83 @@
+From 4ab42809cb34222b1c574c07e083a4008e97d8de Mon Sep 17 00:00:00 2001
+From: "GPT 5.5" <codex@openai.com>
+Date: Tue, 28 Apr 2026 09:30:41 +0800
+Subject: [PATCH] address review feedback and CI failures
+
+Consolidate follow-up fixes from review and CI:
+
+- fix lint and mypy issues in reference log path handling
+- validate remote reference paths before invoking git branch deletion
+- add symlink escape coverage where realpath resolves symlinks
+- ensure temporary test repositories release git resources during cleanup
+
+CVE: CVE-2026-44243
+Upstream-Status: Backport [https://github.com/gitpython-developers/GitPython/commit/4af8463cca31c2369312fcaa5309dfc30756c7b6]
+
+Backport Changes:
+- Omitted test/test_refs.py because the PyPI 3.1.43 source used by
+ the recipe does not ship the upstream test tree.
+
+Co-authored-by: Sebastian Thiel <sebastian.thiel@icloud.com>
+(cherry picked from commit 4af8463cca31c2369312fcaa5309dfc30756c7b6)
+Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
+---
+ git/refs/log.py | 4 +++-
+ git/refs/remote.py | 4 +++-
+ git/util.py | 2 +-
+ 3 files changed, 7 insertions(+), 3 deletions(-)
+
+diff --git a/git/refs/log.py b/git/refs/log.py
+index 88906758..642b1825 100644
+--- a/git/refs/log.py
++++ b/git/refs/log.py
+@@ -4,7 +4,6 @@
+ __all__ = ["RefLog", "RefLogEntry"]
+
+ from mmap import mmap
+-import os.path as osp
+ import re
+ import time as _time
+
+@@ -212,6 +211,9 @@ class RefLog(List[RefLogEntry], Serializable):
+
+ :param ref:
+ :class:`~git.refs.symbolic.SymbolicReference` instance
++
++ :raise ValueError:
++ If `ref.path` is invalid or escapes the repository's reflog directory.
+ """
+ return to_native_path(ref._get_validated_reflog_path(ref.repo, ref.path))
+
+diff --git a/git/refs/remote.py b/git/refs/remote.py
+index 8244470b..e16ae70f 100644
+--- a/git/refs/remote.py
++++ b/git/refs/remote.py
+@@ -58,12 +58,14 @@ class RemoteReference(Head):
+ `kwargs` are given for comparability with the base class method as we
+ should not narrow the signature.
+ """
++ for ref in refs:
++ cls._check_ref_name_valid(ref.path)
++
+ repo.git.branch("-d", "-r", *refs)
+ # The official deletion method will ignore remote symbolic refs - these are
+ # generally ignored in the refs/ folder. We don't though and delete remainders
+ # manually.
+ for ref in refs:
+- cls._check_ref_name_valid(ref.path)
+ try:
+ os.remove(cls._get_validated_path(repo.common_dir, ref.path))
+ except OSError:
+diff --git a/git/util.py b/git/util.py
+index 8c1c2601..27b239ab 100644
+--- a/git/util.py
++++ b/git/util.py
+@@ -289,7 +289,7 @@ def join_path(a: PathLike, *p: PathLike) -> PathLike:
+
+ if sys.platform == "win32":
+
+- def to_native_path_windows(path: PathLike) -> PathLike:
++ def to_native_path_windows(path: PathLike) -> str:
+ path = str(path)
+ return path.replace("/", "\\")
+
diff --git a/meta/recipes-devtools/python/python3-git_3.1.43.bb b/meta/recipes-devtools/python/python3-git_3.1.43.bb
index 26d9a3f0633..ef4f7fa18ca 100644
--- a/meta/recipes-devtools/python/python3-git_3.1.43.bb
+++ b/meta/recipes-devtools/python/python3-git_3.1.43.bb
@@ -15,6 +15,8 @@ inherit pypi python_setuptools_build_meta
SRC_URI += "file://CVE-2026-42284.patch \
file://CVE-2026-42215_p1.patch \
file://CVE-2026-42215_p2.patch \
+ file://CVE-2026-44243_p1.patch \
+ file://CVE-2026-44243_p2.patch \
"
SRC_URI[sha256sum] = "35f314a9f878467f5453cc1fee295c3e18e52f1b99f10f6cf5b1682e968a9e7c"
^ permalink raw reply related [flat|nested] 41+ messages in thread
* [OE-core][wrynose 06/40] python3-git: fix CVE-2026-44244
2026-09-05 20:44 [OE-core][wrynose 00/40] Patch review Yoann Congal
` (4 preceding siblings ...)
2026-09-05 20:44 ` [OE-core][wrynose 05/40] python3-git: fix CVE-2026-44243 Yoann Congal
@ 2026-09-05 20:44 ` Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 07/40] python3-babel: fix CVE_PRODUCT Yoann Congal
` (33 subsequent siblings)
39 siblings, 0 replies; 41+ messages in thread
From: Yoann Congal @ 2026-09-05 20:44 UTC (permalink / raw)
To: openembedded-core
From: Darsh Kelaiya <dkelaiya@cisco.com>
This patch applies the upstream fix as referenced in [3], using all the
backported commits shown in [1] and [2].
[1] https://github.com/gitpython-developers/GitPython/commit/c417af469f9aa3da8dfef78f996c0fb8c5d1f4c2
[2] https://github.com/gitpython-developers/GitPython/commit/8e24503b42c1d63dd98e8b2e6a2f655bdd0821e3
[3] https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-v87r-6q3f-2j67
Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../python3-git/CVE-2026-44244_p1.patch | 102 ++++++++++++++++++
.../python3-git/CVE-2026-44244_p2.patch | 28 +++++
.../python/python3-git_3.1.43.bb | 2 +
3 files changed, 132 insertions(+)
create mode 100644 meta/recipes-devtools/python/python3-git/CVE-2026-44244_p1.patch
create mode 100644 meta/recipes-devtools/python/python3-git/CVE-2026-44244_p2.patch
diff --git a/meta/recipes-devtools/python/python3-git/CVE-2026-44244_p1.patch b/meta/recipes-devtools/python/python3-git/CVE-2026-44244_p1.patch
new file mode 100644
index 00000000000..66ba5e96976
--- /dev/null
+++ b/meta/recipes-devtools/python/python3-git/CVE-2026-44244_p1.patch
@@ -0,0 +1,102 @@
+From 4ac5a1c848582f606655d03bfbc1243fe1754dc8 Mon Sep 17 00:00:00 2001
+From: "GPT 5.5" <codex@openai.com>
+Date: Wed, 29 Apr 2026 05:47:57 +0800
+Subject: [PATCH] reject control chars in written values in configuration
+
+Reject CR, LF, and NUL in GitConfigParser values before writing them
+to git config files (which also is a deviation from Git which escapes them).
+
+GitConfigParser._write() serializes embedded newlines as indented
+continuation lines by replacing "\n" with "\n\t". Git itself skips
+leading whitespace before parsing config tokens, so an injected value
+such as:
+
+ foo
+ [core]
+ hooksPath=/tmp/hooks
+
+is written in a form where the indented "[core]" line is still parsed by
+Git as a real section header. This lets attacker-controlled input passed
+to config_writer().set_value() poison repository config, including
+core.hooksPath, and redirect hook execution for later Git operations.
+
+Fail closed instead of stripping or normalizing these characters. Silent
+normalization can hide unsanitized caller input, and GitPython does not
+currently round-trip Git-style escaped values such as "\n" as embedded
+newlines.
+
+Apply the validation to set_value(), add_value(), and the public set()
+path so callers cannot bypass the safer helper API. Add regression tests
+for the advisory payload and for CR, LF, NUL, and bytes values.
+
+This preserves existing read behavior for config files that already
+contain multiline values while preventing GitPython from writing new
+unsafe values.
+
+CVE: CVE-2026-44244
+Upstream-Status: Backport [https://github.com/gitpython-developers/GitPython/commit/c417af469f9aa3da8dfef78f996c0fb8c5d1f4c2]
+
+Backport Changes:
+- Omitted test/test_config.py because the PyPI 3.1.43 source used
+ by the recipe does not ship the upstream test tree.
+
+Co-authored-by: Sebastian Thiel <sebastian.thiel@icloud.com>
+(cherry picked from commit c417af469f9aa3da8dfef78f996c0fb8c5d1f4c2)
+Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
+---
+ git/config.py | 24 ++++++++++++++++++++++--
+ 1 file changed, 22 insertions(+), 2 deletions(-)
+
+diff --git a/git/config.py b/git/config.py
+index 3ce9b123..d45cc31b 100644
+--- a/git/config.py
++++ b/git/config.py
+@@ -863,6 +863,24 @@ class GitConfigParser(cp.RawConfigParser, metaclass=MetaParserBuilder):
+ return str(value)
+ return force_text(value)
+
++ def _value_to_string_safe(self, value: Union[str, bytes, int, float, bool]) -> str:
++ value_str = self._value_to_string(value)
++ if re.search(r"[\r\n\x00]", value_str):
++ raise ValueError("Git config values must not contain CR, LF, or NUL")
++ return value_str
++
++ @needs_values
++ @set_dirty_and_flush_changes
++ def set(
++ self,
++ section: str,
++ option: str,
++ value: Union[str, bytes, int, float, bool, None] = None,
++ ) -> None:
++ if value is not None:
++ value = self._value_to_string_safe(value)
++ return super().set(section, option, value)
++
+ @needs_values
+ @set_dirty_and_flush_changes
+ def set_value(self, section: str, option: str, value: Union[str, bytes, int, float, bool]) -> "GitConfigParser":
+@@ -883,9 +901,10 @@ class GitConfigParser(cp.RawConfigParser, metaclass=MetaParserBuilder):
+ :return:
+ This instance
+ """
++ value_str = self._value_to_string_safe(value)
+ if not self.has_section(section):
+ self.add_section(section)
+- self.set(section, option, self._value_to_string(value))
++ self.set(section, option, value_str)
+ return self
+
+ @needs_values
+@@ -910,9 +929,10 @@ class GitConfigParser(cp.RawConfigParser, metaclass=MetaParserBuilder):
+ :return:
+ This instance
+ """
++ value_str = self._value_to_string_safe(value)
+ if not self.has_section(section):
+ self.add_section(section)
+- self._sections[section].add(option, self._value_to_string(value))
++ self._sections[section].add(option, value_str)
+ return self
+
+ def rename_section(self, section: str, new_name: str) -> "GitConfigParser":
diff --git a/meta/recipes-devtools/python/python3-git/CVE-2026-44244_p2.patch b/meta/recipes-devtools/python/python3-git/CVE-2026-44244_p2.patch
new file mode 100644
index 00000000000..43aea2fd565
--- /dev/null
+++ b/meta/recipes-devtools/python/python3-git/CVE-2026-44244_p2.patch
@@ -0,0 +1,28 @@
+From cfa5a26453544e93be3689101e710b6b07a6e2b0 Mon Sep 17 00:00:00 2001
+From: "GPT 5.5" <codex@openai.com>
+Date: Wed, 29 Apr 2026 06:39:02 +0800
+Subject: [PATCH] avoid duplicate validation in set_value
+
+CVE: CVE-2026-44244
+Upstream-Status: Backport [https://github.com/gitpython-developers/GitPython/commit/8e24503b42c1d63dd98e8b2e6a2f655bdd0821e3]
+
+Co-authored-by: Sebastian Thiel <sebastian.thiel@icloud.com>
+(cherry picked from commit 8e24503b42c1d63dd98e8b2e6a2f655bdd0821e3)
+Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
+---
+ git/config.py | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/git/config.py b/git/config.py
+index d45cc31b..1595d51f 100644
+--- a/git/config.py
++++ b/git/config.py
+@@ -904,7 +904,7 @@ class GitConfigParser(cp.RawConfigParser, metaclass=MetaParserBuilder):
+ value_str = self._value_to_string_safe(value)
+ if not self.has_section(section):
+ self.add_section(section)
+- self.set(section, option, value_str)
++ super().set(section, option, value_str)
+ return self
+
+ @needs_values
diff --git a/meta/recipes-devtools/python/python3-git_3.1.43.bb b/meta/recipes-devtools/python/python3-git_3.1.43.bb
index ef4f7fa18ca..7534531fa37 100644
--- a/meta/recipes-devtools/python/python3-git_3.1.43.bb
+++ b/meta/recipes-devtools/python/python3-git_3.1.43.bb
@@ -17,6 +17,8 @@ SRC_URI += "file://CVE-2026-42284.patch \
file://CVE-2026-42215_p2.patch \
file://CVE-2026-44243_p1.patch \
file://CVE-2026-44243_p2.patch \
+ file://CVE-2026-44244_p1.patch \
+ file://CVE-2026-44244_p2.patch \
"
SRC_URI[sha256sum] = "35f314a9f878467f5453cc1fee295c3e18e52f1b99f10f6cf5b1682e968a9e7c"
^ permalink raw reply related [flat|nested] 41+ messages in thread
* [OE-core][wrynose 07/40] python3-babel: fix CVE_PRODUCT
2026-09-05 20:44 [OE-core][wrynose 00/40] Patch review Yoann Congal
` (5 preceding siblings ...)
2026-09-05 20:44 ` [OE-core][wrynose 06/40] python3-git: fix CVE-2026-44244 Yoann Congal
@ 2026-09-05 20:44 ` Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 08/40] python3-pycryptodome: " Yoann Congal
` (32 subsequent siblings)
39 siblings, 0 replies; 41+ messages in thread
From: Yoann Congal @ 2026-09-05 20:44 UTC (permalink / raw)
To: openembedded-core
From: Tim Orling <tim.orling@konsulko.com>
Recipe (PV): python3-babel (2.18.0)
Before -> After: python:babel -> pocoo:babel
Newly caught CVEs: CVE-2021-42771 (locale .dat deserialization RCE)
Status: patched (fixed 2.9.1)
AI-Generated: Claude Sonnet 5
Signed-off-by: Tim Orling <tim.orling@konsulko.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit 134175fa92b85e639dc4646d9a88eeaba0fae4d3)
Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
meta/recipes-devtools/python/python3-babel_2.18.0.bb | 2 ++
1 file changed, 2 insertions(+)
diff --git a/meta/recipes-devtools/python/python3-babel_2.18.0.bb b/meta/recipes-devtools/python/python3-babel_2.18.0.bb
index b0abb2c62e7..26847372bf3 100644
--- a/meta/recipes-devtools/python/python3-babel_2.18.0.bb
+++ b/meta/recipes-devtools/python/python3-babel_2.18.0.bb
@@ -7,6 +7,8 @@ SRC_URI[sha256sum] = "b80b99a14bd085fcacfa15c9165f651fbb3406e66cc603abf11c575093
inherit pypi setuptools3
+CVE_PRODUCT = "pocoo:babel"
+
S = "${UNPACKDIR}/babel-${PV}"
CLEANBROKEN = "1"
^ permalink raw reply related [flat|nested] 41+ messages in thread
* [OE-core][wrynose 08/40] python3-pycryptodome: fix CVE_PRODUCT
2026-09-05 20:44 [OE-core][wrynose 00/40] Patch review Yoann Congal
` (6 preceding siblings ...)
2026-09-05 20:44 ` [OE-core][wrynose 07/40] python3-babel: fix CVE_PRODUCT Yoann Congal
@ 2026-09-05 20:44 ` Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 09/40] python3-dbusmock: " Yoann Congal
` (31 subsequent siblings)
39 siblings, 0 replies; 41+ messages in thread
From: Yoann Congal @ 2026-09-05 20:44 UTC (permalink / raw)
To: openembedded-core
From: Tim Orling <tim.orling@konsulko.com>
With this change, 2 Patched CVEs are properly reported:
* CVE-2018-15560
* CVE-2023-52323
Signed-off-by: Tim Orling <tim.orling@konsulko.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit f8a88010edc6edbb168cbc31aa5df847a328661c)
The current pypi default "python:pycryptodome" is deprecated and does
not match current NVD configuration criteria. Use
"pycryptodome:pycryptodome", the active NVD dictionary CPE and
configuration identity for the packaged source, so two patched CVE
records are reported.
Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
meta/recipes-devtools/python/python3-pycryptodome_3.23.0.bb | 1 +
1 file changed, 1 insertion(+)
diff --git a/meta/recipes-devtools/python/python3-pycryptodome_3.23.0.bb b/meta/recipes-devtools/python/python3-pycryptodome_3.23.0.bb
index 2528162ff8a..1b2a5edd38c 100644
--- a/meta/recipes-devtools/python/python3-pycryptodome_3.23.0.bb
+++ b/meta/recipes-devtools/python/python3-pycryptodome_3.23.0.bb
@@ -3,3 +3,4 @@ inherit python_setuptools_build_meta
SRC_URI[sha256sum] = "447700a657182d60338bab09fdb27518f8856aecd80ae4c6bdddb67ff5da44ef"
+CVE_PRODUCT = "pycryptodome:pycryptodome"
^ permalink raw reply related [flat|nested] 41+ messages in thread
* [OE-core][wrynose 09/40] python3-dbusmock: fix CVE_PRODUCT
2026-09-05 20:44 [OE-core][wrynose 00/40] Patch review Yoann Congal
` (7 preceding siblings ...)
2026-09-05 20:44 ` [OE-core][wrynose 08/40] python3-pycryptodome: " Yoann Congal
@ 2026-09-05 20:44 ` Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 10/40] python3-wheel: " Yoann Congal
` (30 subsequent siblings)
39 siblings, 0 replies; 41+ messages in thread
From: Yoann Congal @ 2026-09-05 20:44 UTC (permalink / raw)
To: openembedded-core
From: Tim Orling <tim.orling@konsulko.com>
Recipe (PV): python3-dbusmock (0.38.1)
Before -> After: python:python_dbusmock -> python-dbusmock_project:python-dbusmock
Newly caught CVEs: CVE-2015-1326 (.pyc code exec via AddTemplate)
Status: patched (fixed 0.15.1)
AI-Generated: Claude Sonnet 5
Signed-off-by: Tim Orling <tim.orling@konsulko.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit 0405d7d4e476964239e1c27c987ec9c12372e95f)
Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
meta/recipes-devtools/python/python3-dbusmock_0.38.1.bb | 2 ++
1 file changed, 2 insertions(+)
diff --git a/meta/recipes-devtools/python/python3-dbusmock_0.38.1.bb b/meta/recipes-devtools/python/python3-dbusmock_0.38.1.bb
index cbd74b4059e..ecec075f6f2 100644
--- a/meta/recipes-devtools/python/python3-dbusmock_0.38.1.bb
+++ b/meta/recipes-devtools/python/python3-dbusmock_0.38.1.bb
@@ -11,6 +11,8 @@ PYPI_PACKAGE = "python_dbusmock"
inherit pypi python_setuptools_build_meta
DEPENDS += "python3-setuptools-scm-native"
+CVE_PRODUCT = "python-dbusmock_project:python-dbusmock"
+
RDEPENDS:${PN} += "\
python3-dbus \
python3-unittest \
^ permalink raw reply related [flat|nested] 41+ messages in thread
* [OE-core][wrynose 10/40] python3-wheel: fix CVE_PRODUCT
2026-09-05 20:44 [OE-core][wrynose 00/40] Patch review Yoann Congal
` (8 preceding siblings ...)
2026-09-05 20:44 ` [OE-core][wrynose 09/40] python3-dbusmock: " Yoann Congal
@ 2026-09-05 20:44 ` Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 11/40] python3-click: " Yoann Congal
` (29 subsequent siblings)
39 siblings, 0 replies; 41+ messages in thread
From: Yoann Congal @ 2026-09-05 20:44 UTC (permalink / raw)
To: openembedded-core
From: Tim Orling <tim.orling@konsulko.com>
The proper CVE_PRODUCT is "wheel_project:wheel".
BEFORE: python:wheel -> 0 CVEs
AFTER: wheel_project:wheel -> 2 CVEs
* Already patched at 0.46.3.
- CVE-2022-40898 — DoS in wheel CLI via malicious input. Affects <0.38.1.
- CVE-2026-24049 — malicious wheel file can modify permissions of arbitrary
files. Affects 0.40.0–<0.46.2.
Note: The original commit targeted python3-wheel_0.47.0.bb. This is
adjusted for Wrynose, where the recipe version is 0.46.3.
AI-Generated: Claude Sonnet 5
Signed-off-by: Tim Orling <tim.orling@konsulko.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit fe55278e01bbe434452191109278b436bf008ebc)
Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
meta/recipes-devtools/python/python3-wheel_0.46.3.bb | 2 ++
1 file changed, 2 insertions(+)
diff --git a/meta/recipes-devtools/python/python3-wheel_0.46.3.bb b/meta/recipes-devtools/python/python3-wheel_0.46.3.bb
index 2545e5496e9..7338e8edcd8 100644
--- a/meta/recipes-devtools/python/python3-wheel_0.46.3.bb
+++ b/meta/recipes-devtools/python/python3-wheel_0.46.3.bb
@@ -8,6 +8,8 @@ SRC_URI[sha256sum] = "e3e79874b07d776c40bd6033f8ddf76a7dad46a7b8aa1b2787a8308351
inherit python_flit_core pypi ptest-python-pytest
+CVE_PRODUCT = "wheel_project:wheel"
+
RDEPENDS:${PN} += "python3-packaging"
# One test is skipped but requires the "full" python3-flit, not just python3-flit-core
^ permalink raw reply related [flat|nested] 41+ messages in thread
* [OE-core][wrynose 11/40] python3-click: fix CVE_PRODUCT
2026-09-05 20:44 [OE-core][wrynose 00/40] Patch review Yoann Congal
` (9 preceding siblings ...)
2026-09-05 20:44 ` [OE-core][wrynose 10/40] python3-wheel: " Yoann Congal
@ 2026-09-05 20:44 ` Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 12/40] python3-attrs: " Yoann Congal
` (28 subsequent siblings)
39 siblings, 0 replies; 41+ messages in thread
From: Yoann Congal @ 2026-09-05 20:44 UTC (permalink / raw)
To: openembedded-core
From: Tim Orling <tim.orling@konsulko.com>
Recipe (PV): python3-click (8.3.1)
Before -> After python:click -> palletsprojects:click
Newly caught: CVE-2026-7246 (command injection in click.edit())
Status: unpatched (fixed 8.3.3)
Note: The original commit targeted python3-click_8.4.2.bb. This is
adjusted for Wrynose, where the recipe version is 8.3.1. The unrelated
DESCRIPTION cleanup from the original commit is intentionally omitted.
AI-Generated: Claude Sonnet 5
Signed-off-by: Tim Orling <tim.orling@konsulko.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit 30357a26d7ce490725d1b0ac3375047d00595a5c)
Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
meta/recipes-devtools/python/python3-click_8.3.1.bb | 2 ++
1 file changed, 2 insertions(+)
diff --git a/meta/recipes-devtools/python/python3-click_8.3.1.bb b/meta/recipes-devtools/python/python3-click_8.3.1.bb
index 1f42fe1a50c..49204e96e1f 100644
--- a/meta/recipes-devtools/python/python3-click_8.3.1.bb
+++ b/meta/recipes-devtools/python/python3-click_8.3.1.bb
@@ -12,6 +12,8 @@ SRC_URI[sha256sum] = "12ff4785d337a1bb490bb7e9c2b1ee5da3112e94a8622f26a6c77f5d2f
inherit pypi python_flit_core ptest-python-pytest
+CVE_PRODUCT = "palletsprojects:click"
+
RDEPENDS:${PN}-ptest += " \
python3-pytest \
python3-terminal \
^ permalink raw reply related [flat|nested] 41+ messages in thread
* [OE-core][wrynose 12/40] python3-attrs: fix CVE_PRODUCT
2026-09-05 20:44 [OE-core][wrynose 00/40] Patch review Yoann Congal
` (10 preceding siblings ...)
2026-09-05 20:44 ` [OE-core][wrynose 11/40] python3-click: " Yoann Congal
@ 2026-09-05 20:44 ` Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 13/40] python3-numpy: " Yoann Congal
` (27 subsequent siblings)
39 siblings, 0 replies; 41+ messages in thread
From: Yoann Congal @ 2026-09-05 20:44 UTC (permalink / raw)
To: openembedded-core
From: Tim Orling <tim.orling@konsulko.com>
No new CVEs are caught, but attrs_project:attrs matches the upstream
NVD dictionary CPE. The pypi.bbclass default "python:attrs" generates
the wrong product identity for the packaged attrs source.
This changes the generated product identity, but the Wrynose
sbom-cve-check database snapshot has no current CVE report delta.
Note: The original commit targeted python3-attrs_26.1.0.bb. This is
adjusted for Wrynose, where the recipe version is 25.4.0.
AI-Generated: Claude Sonnet 5
Signed-off-by: Tim Orling <tim.orling@konsulko.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit bc07eddb82fe42ecf86e685450ec0b5c9d3a9ce1)
Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
meta/recipes-devtools/python/python3-attrs_25.4.0.bb | 2 ++
1 file changed, 2 insertions(+)
diff --git a/meta/recipes-devtools/python/python3-attrs_25.4.0.bb b/meta/recipes-devtools/python/python3-attrs_25.4.0.bb
index 7bc581b8759..c3f5a155ca0 100644
--- a/meta/recipes-devtools/python/python3-attrs_25.4.0.bb
+++ b/meta/recipes-devtools/python/python3-attrs_25.4.0.bb
@@ -7,6 +7,8 @@ SRC_URI[sha256sum] = "16d5969b87f0859ef33a48b35d55ac1be6e42ae49d5e853b597db70c35
inherit pypi ptest-python-pytest python_hatchling
+CVE_PRODUCT = "attrs_project:attrs"
+
DEPENDS += " \
python3-hatch-vcs-native \
python3-hatch-fancy-pypi-readme-native \
^ permalink raw reply related [flat|nested] 41+ messages in thread
* [OE-core][wrynose 13/40] python3-numpy: fix CVE_PRODUCT
2026-09-05 20:44 [OE-core][wrynose 00/40] Patch review Yoann Congal
` (11 preceding siblings ...)
2026-09-05 20:44 ` [OE-core][wrynose 12/40] python3-attrs: " Yoann Congal
@ 2026-09-05 20:44 ` Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 14/40] python3-pycryptodomex: " Yoann Congal
` (26 subsequent siblings)
39 siblings, 0 replies; 41+ messages in thread
From: Yoann Congal @ 2026-09-05 20:44 UTC (permalink / raw)
To: openembedded-core
From: Tim Orling <tim.orling@konsulko.com>
Without this change, 0 CVEs are reported.
With this change, 8 Patched CVEs are reported:
* CVE-2014-1858
* CVE-2014-1859
* CVE-2017-12852
* CVE-2019-6446
* CVE-2021-33430
* CVE-2021-34141
* CVE-2021-41495
* CVE-2021-41496
This can be verified with a query like:
$ cat .../core-image-ptest-python3-numpy-*.rootfs.sbom-cve-check.yocto.json \
| jq '.package[] | select(.name == "python3-numpy") \
| .issue[] | {id: .id, status: .status}'
Signed-off-by: Tim Orling <tim.orling@konsulko.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit ad623e71fadeddcb0b70bba8fbf28c75a976e596)
The current "python3-numpy" mapping has no matching NVD CPE or
configuration identity, so eight source-aligned CVE records are missed.
Use "numpy:numpy", the active NVD dictionary CPE and configuration
identity for the packaged NumPy source.
Note: The original commit targeted python3-numpy_2.5.2.bb. This is
adjusted for Wrynose, where the recipe version is 2.4.3.
Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
meta/recipes-devtools/python/python3-numpy_2.4.3.bb | 2 ++
1 file changed, 2 insertions(+)
diff --git a/meta/recipes-devtools/python/python3-numpy_2.4.3.bb b/meta/recipes-devtools/python/python3-numpy_2.4.3.bb
index 7521a93f990..f34723b2c26 100644
--- a/meta/recipes-devtools/python/python3-numpy_2.4.3.bb
+++ b/meta/recipes-devtools/python/python3-numpy_2.4.3.bb
@@ -18,6 +18,8 @@ SRC_URI[sha256sum] = "483a201202b73495f00dbc83796c6ae63137a9bdade074f7648b3e3261
GITHUB_BASE_URI = "https://github.com/numpy/numpy/releases"
UPSTREAM_CHECK_REGEX = "releases/tag/v?(?P<pver>\d+(\.\d+)+)$"
+CVE_PRODUCT = "numpy:numpy"
+
inherit pkgconfig ptest python_mesonpy github-releases cython
S = "${UNPACKDIR}/numpy-${PV}"
^ permalink raw reply related [flat|nested] 41+ messages in thread
* [OE-core][wrynose 14/40] python3-pycryptodomex: fix CVE_PRODUCT
2026-09-05 20:44 [OE-core][wrynose 00/40] Patch review Yoann Congal
` (12 preceding siblings ...)
2026-09-05 20:44 ` [OE-core][wrynose 13/40] python3-numpy: " Yoann Congal
@ 2026-09-05 20:44 ` Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 15/40] python3-mako: upgrade 1.3.10 -> 1.3.12 Yoann Congal
` (25 subsequent siblings)
39 siblings, 0 replies; 41+ messages in thread
From: Yoann Congal @ 2026-09-05 20:44 UTC (permalink / raw)
To: openembedded-core
From: Tim Orling <tim.orling@konsulko.com>
With this change, 1 Patched CVE is properly reported:
* CVE-2023-52323
Signed-off-by: Tim Orling <tim.orling@konsulko.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit c2a2ae48add874f41c5b60ca90ba3a26ebb0fe38)
The current pypi default "python:pycryptodomex" has no matching NVD CPE
or configuration identity. Use "pycryptodome:pycryptodomex", the active
NVD dictionary CPE and configuration identity for the packaged
distribution, so CVE-2023-52323 is properly reported as patched.
Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
meta/recipes-devtools/python/python3-pycryptodomex_3.23.0.bb | 2 ++
1 file changed, 2 insertions(+)
diff --git a/meta/recipes-devtools/python/python3-pycryptodomex_3.23.0.bb b/meta/recipes-devtools/python/python3-pycryptodomex_3.23.0.bb
index 43dba3faa3c..148409c8d96 100644
--- a/meta/recipes-devtools/python/python3-pycryptodomex_3.23.0.bb
+++ b/meta/recipes-devtools/python/python3-pycryptodomex_3.23.0.bb
@@ -3,6 +3,8 @@ inherit python_setuptools_build_meta
SRC_URI[sha256sum] = "71909758f010c82bc99b0abf4ea12012c98962fbf0583c2164f8b84533c2e4da"
+CVE_PRODUCT = "pycryptodome:pycryptodomex"
+
FILES:${PN}-tests = " \
${PYTHON_SITEPACKAGES_DIR}/Cryptodome/SelfTest/ \
${PYTHON_SITEPACKAGES_DIR}/Cryptodome/SelfTest/__pycache__/ \
^ permalink raw reply related [flat|nested] 41+ messages in thread
* [OE-core][wrynose 15/40] python3-mako: upgrade 1.3.10 -> 1.3.12
2026-09-05 20:44 [OE-core][wrynose 00/40] Patch review Yoann Congal
` (13 preceding siblings ...)
2026-09-05 20:44 ` [OE-core][wrynose 14/40] python3-pycryptodomex: " Yoann Congal
@ 2026-09-05 20:44 ` Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 16/40] gnutls: fix for CVE-2026-42011 Yoann Congal
` (24 subsequent siblings)
39 siblings, 0 replies; 41+ messages in thread
From: Yoann Congal @ 2026-09-05 20:44 UTC (permalink / raw)
To: openembedded-core
From: Richard Purdie <richard.purdie@linuxfoundation.org>
ChangeLog:https://docs.makotemplates.org/en/latest/changelog.html#change-1.3.12
(cherry picked from commit 439b05aa55a7d4d71b81ca93025de1b28d79b311)
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../python/{python3-mako_1.3.10.bb => python3-mako_1.3.12.bb} | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
rename meta/recipes-devtools/python/{python3-mako_1.3.10.bb => python3-mako_1.3.12.bb} (88%)
diff --git a/meta/recipes-devtools/python/python3-mako_1.3.10.bb b/meta/recipes-devtools/python/python3-mako_1.3.12.bb
similarity index 88%
rename from meta/recipes-devtools/python/python3-mako_1.3.10.bb
rename to meta/recipes-devtools/python/python3-mako_1.3.12.bb
index 2d937dc184e..b2c1a8dad8d 100644
--- a/meta/recipes-devtools/python/python3-mako_1.3.10.bb
+++ b/meta/recipes-devtools/python/python3-mako_1.3.12.bb
@@ -8,7 +8,7 @@ PYPI_PACKAGE = "mako"
inherit pypi python_setuptools_build_meta ptest-python-pytest
-SRC_URI[sha256sum] = "99579a6f39583fa7e5630a28c3c1f440e4e97a414b80372649c0ce338da2ea28"
+SRC_URI[sha256sum] = "9f778e93289bd410bb35daadeb4fc66d95a746f0b75777b942088b7fd7af550a"
RDEPENDS:${PN} = "python3-html \
python3-markupsafe \
^ permalink raw reply related [flat|nested] 41+ messages in thread
* [OE-core][wrynose 16/40] gnutls: fix for CVE-2026-42011
2026-09-05 20:44 [OE-core][wrynose 00/40] Patch review Yoann Congal
` (14 preceding siblings ...)
2026-09-05 20:44 ` [OE-core][wrynose 15/40] python3-mako: upgrade 1.3.10 -> 1.3.12 Yoann Congal
@ 2026-09-05 20:44 ` Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 17/40] gnutls: fix CVE-2026-42010 Yoann Congal
` (23 subsequent siblings)
39 siblings, 0 replies; 41+ messages in thread
From: Yoann Congal @ 2026-09-05 20:44 UTC (permalink / raw)
To: openembedded-core
From: Jakub Szczudlo (Nokia) <jakub.szczudlo@nokia.com>
Backport patches to fix CVE-2026-42011 and extend test for it
References:
https://nvd.nist.gov/vuln/detail/CVE-2026-42011
Upstream fix:
https://gitlab.com/gnutls/gnutls/-/commit/1dead2faec6320aaba321eb56f20d442df192b83
https://gitlab.com/gnutls/gnutls/-/commit/24713b8c63137ce0665b495d22ccce4f5ce05c84
Tested with ptest
Signed-off-by: Jakub Szczudlo <jakub.szczudlo@nokia.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../gnutls/gnutls/CVE-2026-42011_p1.patch | 43 ++++++
.../gnutls/gnutls/CVE-2026-42011_p2.patch | 141 ++++++++++++++++++
meta/recipes-support/gnutls/gnutls_3.8.12.bb | 2 +
3 files changed, 186 insertions(+)
create mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2026-42011_p1.patch
create mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2026-42011_p2.patch
diff --git a/meta/recipes-support/gnutls/gnutls/CVE-2026-42011_p1.patch b/meta/recipes-support/gnutls/gnutls/CVE-2026-42011_p1.patch
new file mode 100644
index 00000000000..62a9714c6c6
--- /dev/null
+++ b/meta/recipes-support/gnutls/gnutls/CVE-2026-42011_p1.patch
@@ -0,0 +1,43 @@
+From 1dead2faec6320aaba321eb56f20d442df192b83 Mon Sep 17 00:00:00 2001
+From: Alexander Sosedkin <asosedkin@redhat.com>
+Date: Tue, 14 Apr 2026 17:41:30 +0200
+Subject: [PATCH 1/2] x509/name_constraints: fix intersecting empty constraints
+
+Permitted name constraints were wrongfully ignored
+when prior CAs only had excluded name constraints,
+resulting in a name constraint bypass.
+
+With this change, they are taken into account and propagate.
+
+CVE: CVE-2026-42011
+Upstream-Status: Backport [https://gitlab.com/gnutls/gnutls/-/commit/1dead2faec6320aaba321eb56f20d442df192b83]
+
+Reported-by: Haruto Kimura (Stella)
+Fixes: #1824
+Fixes: CVE-2026-42011
+Fixes: GNUTLS-SA-2026-04-29-6
+CVSS: 4.8 Medium CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
+
+Signed-off-by: Alexander Sosedkin <asosedkin@redhat.com>
+Signed-off-by: Jakub Szczudlo <jakub.szczudlo@nokia.com>
+---
+ lib/x509/name_constraints.c | 3 ---
+ 1 file changed, 3 deletions(-)
+
+diff --git a/lib/x509/name_constraints.c b/lib/x509/name_constraints.c
+index 04722bdf4..232d466c4 100644
+--- a/lib/x509/name_constraints.c
++++ b/lib/x509/name_constraints.c
+@@ -723,9 +723,6 @@ static int name_constraints_node_list_intersect(
+ type_bitmask_t types_in_p1 = 0, types_in_p2 = 0;
+ static const unsigned char universal_ip[32] = { 0 };
+
+- if (permitted->size == 0 || permitted2->size == 0)
+- return GNUTLS_E_SUCCESS;
+-
+ /* make sorted views of the arrays */
+ ret = ensure_sorted(permitted);
+ if (ret < 0) {
+--
+2.53.0
+
diff --git a/meta/recipes-support/gnutls/gnutls/CVE-2026-42011_p2.patch b/meta/recipes-support/gnutls/gnutls/CVE-2026-42011_p2.patch
new file mode 100644
index 00000000000..29eb6bda43a
--- /dev/null
+++ b/meta/recipes-support/gnutls/gnutls/CVE-2026-42011_p2.patch
@@ -0,0 +1,141 @@
+From 24713b8c63137ce0665b495d22ccce4f5ce05c84 Mon Sep 17 00:00:00 2001
+From: Alexander Sosedkin <asosedkin@redhat.com>
+Date: Tue, 14 Apr 2026 17:49:50 +0200
+Subject: [PATCH 2/2] tests/name-constraints-merge: extend to cover #1824
+
+CVE: CVE-2026-42011
+Upstream-Status: Backport [https://gitlab.com/gnutls/gnutls/-/commit/24713b8c63137ce0665b495d22ccce4f5ce05c84]
+
+Signed-off-by: Alexander Sosedkin <asosedkin@redhat.com>
+Signed-off-by: Jakub Szczudlo <jakub.szczudlo@nokia.com>
+---
+ tests/name-constraints-merge.c | 113 +++++++++++++++++++++++++++++++++
+ 1 file changed, 113 insertions(+)
+
+diff --git a/tests/name-constraints-merge.c b/tests/name-constraints-merge.c
+index 70376aaa7..3ff8d6c60 100644
+--- a/tests/name-constraints-merge.c
++++ b/tests/name-constraints-merge.c
+@@ -473,6 +473,119 @@ void doit(void)
+ gnutls_x509_name_constraints_deinit(nc1);
+ gnutls_x509_name_constraints_deinit(nc2);
+
++ /* 6: test intersecting empty permitted with non-empty permitted
++ * NC1: excluded DNS excluded.example.org (empty permitted)
++ * NC2: permitted DNS permitted.example.org
++ * Expected result:
++ * permitted=[permitted.example.org], excluded=[excluded.example.org]
++ * unrelated.example.com is rejected
++ */
++ suite = 6;
++
++ ret = gnutls_x509_name_constraints_init(&nc1);
++ check_for_error(ret);
++
++ ret = gnutls_x509_name_constraints_init(&nc2);
++ check_for_error(ret);
++
++ set_name("excluded.example.org", &name);
++ ret = gnutls_x509_name_constraints_add_excluded(nc1, GNUTLS_SAN_DNSNAME,
++ &name);
++ check_for_error(ret);
++
++ set_name("permitted.example.org", &name);
++ ret = gnutls_x509_name_constraints_add_permitted(
++ nc2, GNUTLS_SAN_DNSNAME, &name);
++ check_for_error(ret);
++
++ ret = _gnutls_x509_name_constraints_merge(nc1, nc2);
++ check_for_error(ret);
++
++ set_name("unrelated.example.com", &name); /* entirely unrelated */
++ ret = gnutls_x509_name_constraints_check(nc1, GNUTLS_SAN_DNSNAME,
++ &name);
++ check_test_result(suite, ret, NAME_REJECTED, &name); /* #1814 */
++
++ set_name("permitted.example.org", &name); /* permitted, direct */
++ ret = gnutls_x509_name_constraints_check(nc1, GNUTLS_SAN_DNSNAME,
++ &name);
++ check_test_result(suite, ret, NAME_ACCEPTED, &name); /* sanity */
++
++ set_name("sub.permitted.example.org", &name); /* permitted, subdomain */
++ ret = gnutls_x509_name_constraints_check(nc1, GNUTLS_SAN_DNSNAME,
++ &name);
++ check_test_result(suite, ret, NAME_ACCEPTED, &name); /* sanity */
++
++ set_name("excluded.example.org", &name); /* excluded, direct */
++ ret = gnutls_x509_name_constraints_check(nc1, GNUTLS_SAN_DNSNAME,
++ &name);
++ check_test_result(suite, ret, NAME_REJECTED, &name); /* sanity */
++
++ set_name("sub.excluded.example.org", &name); /* excluded, subdomain */
++ ret = gnutls_x509_name_constraints_check(nc1, GNUTLS_SAN_DNSNAME,
++ &name);
++ check_test_result(suite, ret, NAME_REJECTED, &name); /* sanity */
++
++ gnutls_x509_name_constraints_deinit(nc1);
++ gnutls_x509_name_constraints_deinit(nc2);
++
++ /* 7: test intersecting non-empty permitted with empty permitted
++ * (same as 6, but swapped to ensure order doesn't matter)
++ * NC1: permitted DNS permitted.example.org
++ * NC2: excluded DNS excluded.example.org (empty permitted)
++ * Expected result:
++ * permitted=[permitted.example.org], excluded=[excluded.example.org]
++ * unrelated.example.com is rejected
++ */
++ suite = 7;
++
++ ret = gnutls_x509_name_constraints_init(&nc1);
++ check_for_error(ret);
++
++ ret = gnutls_x509_name_constraints_init(&nc2);
++ check_for_error(ret);
++
++ set_name("permitted.example.org", &name);
++ ret = gnutls_x509_name_constraints_add_permitted(
++ nc1, GNUTLS_SAN_DNSNAME, &name);
++ check_for_error(ret);
++
++ set_name("excluded.example.org", &name);
++ ret = gnutls_x509_name_constraints_add_excluded(nc2, GNUTLS_SAN_DNSNAME,
++ &name);
++ check_for_error(ret);
++
++ ret = _gnutls_x509_name_constraints_merge(nc1, nc2);
++ check_for_error(ret);
++
++ set_name("unrelated.example.com", &name); /* entirely unrelated */
++ ret = gnutls_x509_name_constraints_check(nc1, GNUTLS_SAN_DNSNAME,
++ &name);
++ check_test_result(suite, ret, NAME_REJECTED, &name); /* #1814 */
++
++ set_name("permitted.example.org", &name); /* permitted, direct */
++ ret = gnutls_x509_name_constraints_check(nc1, GNUTLS_SAN_DNSNAME,
++ &name);
++ check_test_result(suite, ret, NAME_ACCEPTED, &name); /* sanity */
++
++ set_name("sub.permitted.example.org", &name); /* permitted, subdomain */
++ ret = gnutls_x509_name_constraints_check(nc1, GNUTLS_SAN_DNSNAME,
++ &name);
++ check_test_result(suite, ret, NAME_ACCEPTED, &name); /* sanity */
++
++ set_name("excluded.example.org", &name); /* excluded, direct */
++ ret = gnutls_x509_name_constraints_check(nc1, GNUTLS_SAN_DNSNAME,
++ &name);
++ check_test_result(suite, ret, NAME_REJECTED, &name); /* sanity */
++
++ set_name("sub.excluded.example.org", &name); /* excluded, subdomain */
++ ret = gnutls_x509_name_constraints_check(nc1, GNUTLS_SAN_DNSNAME,
++ &name);
++ check_test_result(suite, ret, NAME_REJECTED, &name); /* sanity */
++
++ gnutls_x509_name_constraints_deinit(nc1);
++ gnutls_x509_name_constraints_deinit(nc2);
++
+ /* Test footer */
+
+ if (debug)
+--
+2.53.0
+
diff --git a/meta/recipes-support/gnutls/gnutls_3.8.12.bb b/meta/recipes-support/gnutls/gnutls_3.8.12.bb
index 3ad011742e4..e9059a4bc16 100644
--- a/meta/recipes-support/gnutls/gnutls_3.8.12.bb
+++ b/meta/recipes-support/gnutls/gnutls_3.8.12.bb
@@ -37,6 +37,8 @@ SRC_URI = "https://www.gnupg.org/ftp/gcrypt/gnutls/v${SHRT_VER}/gnutls-${PV}.tar
file://CVE-2026-42009_p1.patch \
file://CVE-2026-42009_p2.patch \
file://CVE-2026-3833.patch \
+ file://CVE-2026-42011_p1.patch \
+ file://CVE-2026-42011_p2.patch \
"
SRC_URI[sha256sum] = "a7b341421bfd459acf7a374ca4af3b9e06608dcd7bd792b2bf470bea012b8e51"
^ permalink raw reply related [flat|nested] 41+ messages in thread
* [OE-core][wrynose 17/40] gnutls: fix CVE-2026-42010
2026-09-05 20:44 [OE-core][wrynose 00/40] Patch review Yoann Congal
` (15 preceding siblings ...)
2026-09-05 20:44 ` [OE-core][wrynose 16/40] gnutls: fix for CVE-2026-42011 Yoann Congal
@ 2026-09-05 20:44 ` Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 18/40] alsa-lib: patch CVE-2026-56109 Yoann Congal
` (22 subsequent siblings)
39 siblings, 0 replies; 41+ messages in thread
From: Yoann Congal @ 2026-09-05 20:44 UTC (permalink / raw)
To: openembedded-core
From: Jakub Szczudlo (Nokia) <jakub.szczudlo@nokia.com>
Backport patch to fix CVE-2026-42010.
References:
https://nvd.nist.gov/vuln/detail/CVE-2026-42010
Upstream fix:
https://gitlab.com/gnutls/gnutls/-/commit/cb1833afd9b6309563211b1c0a7c291f52ca98d5
Tested with ptest
Signed-off-by: Jakub Szczudlo <jakub.szczudlo@nokia.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../gnutls/gnutls/CVE-2026-42010.patch | 41 +++++++++++++++++++
meta/recipes-support/gnutls/gnutls_3.8.12.bb | 1 +
2 files changed, 42 insertions(+)
create mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2026-42010.patch
diff --git a/meta/recipes-support/gnutls/gnutls/CVE-2026-42010.patch b/meta/recipes-support/gnutls/gnutls/CVE-2026-42010.patch
new file mode 100644
index 00000000000..b94a32afffc
--- /dev/null
+++ b/meta/recipes-support/gnutls/gnutls/CVE-2026-42010.patch
@@ -0,0 +1,41 @@
+From cb1833afd9b6309563211b1c0a7c291f52ca98d5 Mon Sep 17 00:00:00 2001
+From: Alexander Sosedkin <asosedkin@redhat.com>
+Date: Tue, 21 Apr 2026 19:26:10 +0200
+Subject: [PATCH] lib/auth/rsa_psk: fix binary PSK identity lookup
+
+A server looking up PSK username with a NUL-character in it
+was wrongfully matching username truncated at a NUL-character.
+Fix the check to compare up to the full username length.
+
+CVE: CVE-2026-42010
+Upstream-Status: Backport [https://gitlab.com/gnutls/gnutls/-/commit/cb1833afd9b6309563211b1c0a7c291f52ca98d5]
+
+Reported-by: Joshua Rogers of AISLE Research Team <joshua@joshua.hu>
+Fixes: #1850
+Fixes: CVE-2026-42010
+Fixes: GNUTLS-SA-2026-04-29-4
+CVSS: 7.1 High CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
+Signed-off-by: Alexander Sosedkin <asosedkin@redhat.com>
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+Signed-off-by: Jakub Szczudlo <jakub.szczudlo@nokia.com>
+---
+ lib/auth/rsa_psk.c | 3 +--
+ 1 file changed, 1 insertion(+), 2 deletions(-)
+
+diff --git a/lib/auth/rsa_psk.c b/lib/auth/rsa_psk.c
+index cc92b4aa96..27caf18769 100644
+--- a/lib/auth/rsa_psk.c
++++ b/lib/auth/rsa_psk.c
+@@ -321,8 +321,7 @@ static int _gnutls_proc_rsa_psk_client_kx(gnutls_session_t session,
+ * filled in if the key is not found.
+ */
+ ret = _gnutls_psk_pwd_find_entry(session, info->username,
+- strlen(info->username), &pwd_psk,
+- NULL);
++ info->username_len, &pwd_psk, NULL);
+ if (ret < 0)
+ return gnutls_assert_val(ret);
+
+--
+GitLab
+
diff --git a/meta/recipes-support/gnutls/gnutls_3.8.12.bb b/meta/recipes-support/gnutls/gnutls_3.8.12.bb
index e9059a4bc16..51ef394dfcf 100644
--- a/meta/recipes-support/gnutls/gnutls_3.8.12.bb
+++ b/meta/recipes-support/gnutls/gnutls_3.8.12.bb
@@ -39,6 +39,7 @@ SRC_URI = "https://www.gnupg.org/ftp/gcrypt/gnutls/v${SHRT_VER}/gnutls-${PV}.tar
file://CVE-2026-3833.patch \
file://CVE-2026-42011_p1.patch \
file://CVE-2026-42011_p2.patch \
+ file://CVE-2026-42010.patch \
"
SRC_URI[sha256sum] = "a7b341421bfd459acf7a374ca4af3b9e06608dcd7bd792b2bf470bea012b8e51"
^ permalink raw reply related [flat|nested] 41+ messages in thread
* [OE-core][wrynose 18/40] alsa-lib: patch CVE-2026-56109
2026-09-05 20:44 [OE-core][wrynose 00/40] Patch review Yoann Congal
` (16 preceding siblings ...)
2026-09-05 20:44 ` [OE-core][wrynose 17/40] gnutls: fix CVE-2026-42010 Yoann Congal
@ 2026-09-05 20:44 ` Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 19/40] libevent: upgrade 2.1.12 -> 2.1.13 Yoann Congal
` (21 subsequent siblings)
39 siblings, 0 replies; 41+ messages in thread
From: Yoann Congal @ 2026-09-05 20:44 UTC (permalink / raw)
To: openembedded-core
From: Peter Marko <peter.marko@siemens.com>
Pick patch listed in NVD CVE report.
Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../alsa/alsa-lib/CVE-2026-56109.patch | 33 +++++++++++++++++++
.../alsa/alsa-lib_1.2.15.3.bb | 1 +
2 files changed, 34 insertions(+)
create mode 100644 meta/recipes-multimedia/alsa/alsa-lib/CVE-2026-56109.patch
diff --git a/meta/recipes-multimedia/alsa/alsa-lib/CVE-2026-56109.patch b/meta/recipes-multimedia/alsa/alsa-lib/CVE-2026-56109.patch
new file mode 100644
index 00000000000..c6ecc837f88
--- /dev/null
+++ b/meta/recipes-multimedia/alsa/alsa-lib/CVE-2026-56109.patch
@@ -0,0 +1,33 @@
+From 536dd6f8affdf5197c12a63a71c92a70b2833cc0 Mon Sep 17 00:00:00 2001
+From: Jaroslav Kysela <perex@perex.cz>
+Date: Mon, 8 Jun 2026 14:33:19 +0200
+Subject: [PATCH] conf: add missing return value check in parse_def()
+
+A malformed configuration may cause SIGSEGV.
+
+Link: https://lore.kernel.org/alsa-devel/CAGt8pqBU0p2voB+qHxWGcNJrKHAcBhAyHUUBPLBN-Yj_SiV6MQ@mail.gmail.com/
+Reported-by: Luigino Camastra <luigino.camastra@aisle.com>
+Signed-off-by: Jaroslav Kysela <perex@perex.cz>
+
+CVE: CVE-2026-56109
+Upstream-Status: Backport [https://github.com/alsa-project/alsa-lib/commit/536dd6f8affdf5197c12a63a71c92a70b2833cc0]
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+---
+ src/conf.c | 4 ++++
+ 1 file changed, 4 insertions(+)
+
+diff --git a/src/conf.c b/src/conf.c
+index b0dd6298..e1dba23d 100644
+--- a/src/conf.c
++++ b/src/conf.c
+@@ -1485,6 +1485,10 @@ static int parse_def(snd_config_t *parent, input_t *input, int skip, int overrid
+ endchr = ']';
+ }
+ c = get_nonwhite(input);
++ if (c < 0) {
++ err = c;
++ goto __end;
++ }
+ if (c != endchr) {
+ if (n)
+ snd_config_delete(n);
diff --git a/meta/recipes-multimedia/alsa/alsa-lib_1.2.15.3.bb b/meta/recipes-multimedia/alsa/alsa-lib_1.2.15.3.bb
index 1ebb3569256..04976f3bf77 100644
--- a/meta/recipes-multimedia/alsa/alsa-lib_1.2.15.3.bb
+++ b/meta/recipes-multimedia/alsa/alsa-lib_1.2.15.3.bb
@@ -11,6 +11,7 @@ LIC_FILES_CHKSUM = "file://COPYING;md5=a916467b91076e631dd8edb7424769c7 \
SRC_URI = "https://www.alsa-project.org/files/pub/lib/${BP}.tar.bz2"
SRC_URI += "file://CVE-2026-25068.patch"
+SRC_URI += "file://CVE-2026-56109.patch"
SRC_URI[sha256sum] = "7b079d614d582cade7ab8db2364e65271d0877a37df8757ac4ac0c8970be861e"
inherit autotools pkgconfig
^ permalink raw reply related [flat|nested] 41+ messages in thread
* [OE-core][wrynose 19/40] libevent: upgrade 2.1.12 -> 2.1.13
2026-09-05 20:44 [OE-core][wrynose 00/40] Patch review Yoann Congal
` (17 preceding siblings ...)
2026-09-05 20:44 ` [OE-core][wrynose 18/40] alsa-lib: patch CVE-2026-56109 Yoann Congal
@ 2026-09-05 20:44 ` Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 20/40] libevent: set status for CVE-2026-63380 Yoann Congal
` (20 subsequent siblings)
39 siblings, 0 replies; 41+ messages in thread
From: Yoann Congal @ 2026-09-05 20:44 UTC (permalink / raw)
To: openembedded-core
From: Ross Burton <ross.burton@arm.com>
Security Fixes (evtag, evrpc):
Fix an out-of-bounds read in decode_tag_internal.
(Found by Brubbish. GHSA-fj29-64w6-73h6)
Fix an integer overflow in evtag_unmarshal_header.
(Found by Brubbish. GHSA-45c6-qx49-89m8)
Security Fixes (evhttp):
Discard HTTP trailers, to prevent header smuggling attacks.
(Found by sebastianosrt. GHSA-2gmv-p5m7-98p6)
Restrict HTTP header parsing to prevent request smuggling.
(Originally reported by xclow3n; and then by kodareef5,
nstaller0490, AsafMeizneer, and yaotushaozhu.
GHSA-q39v-w2g7-gr8j.)
Treat CRLF and %00 more strictly in HTTP headers, to prevent
parser mismatch attacks.
(Reported by xclow3n and AsafMeizner. See GHSA-q39v-w2g7-gr8j,
GHSA-jcwh-pvf2-73p2.)
Fix a heap out-of-bound write that could occur when using
AF_UNIX sockets and compiling libevent with -DNDEBUG.
(Found by mat-mo. GHSA-cvq5-vrvr-j338)
Security fixes (evbuffer, bufferevent):
Fixed a dangling pointer in evbuffer_add_reference.
(Found by DarkaMaul. GHSA-c2pj-cg4r-88c8)
Security fixes (evdns):
Fix an out-of-bounds write in dnsname_to_labels
when building a DNS response of 2^16 bytes.
(Found by sectroyer. GHSA-58rx-7448-jw47)
Security fixes (example code):
Avoid using strcpy() in sample/http-server.c.
(Reported by sectroyer. GHSA-5rgj-2c58-7jrc.)
Signed-off-by: Ross Burton <ross.burton@arm.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(From OE-Core rev: 9ae7030db6f5c415de94b6d85eaac418ae1e0f7b)
Full release notes:
* https://github.com/libevent/libevent/releases/tag/release-2.1.13-stable
Unpatched CVE statuses will get fixed with backport of latest cve-tooling.
Removed github style user references.
Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
...s_dns.c-patch-out-tests-that-require-a-wo.patch | 8 ++++----
...s.h-Increase-default-timeval-tolerance-50.patch | 10 +++++-----
...-util-monotonic_prc_fallback-as-retriable.patch | 11 ++++-------
...e-tests-are-marked-failed-only-when-all-a.patch | 9 +++------
.../libevent/Makefile-missing-test-dir.patch | 14 ++++++++++----
.../{libevent_2.1.12.bb => libevent_2.1.13.bb} | 2 +-
6 files changed, 27 insertions(+), 27 deletions(-)
rename meta/recipes-support/libevent/{libevent_2.1.12.bb => libevent_2.1.13.bb} (95%)
diff --git a/meta/recipes-support/libevent/libevent/0001-test-regress_dns.c-patch-out-tests-that-require-a-wo.patch b/meta/recipes-support/libevent/libevent/0001-test-regress_dns.c-patch-out-tests-that-require-a-wo.patch
index 505153d285e..bab94a17ecd 100644
--- a/meta/recipes-support/libevent/libevent/0001-test-regress_dns.c-patch-out-tests-that-require-a-wo.patch
+++ b/meta/recipes-support/libevent/libevent/0001-test-regress_dns.c-patch-out-tests-that-require-a-wo.patch
@@ -1,4 +1,4 @@
-From 7c17967b8fd2d18b74a8934fd9bb8212ebd6a271 Mon Sep 17 00:00:00 2001
+From 3444b04844a0cd75050d16e9382427f0f431a948 Mon Sep 17 00:00:00 2001
From: Alexander Kanavin <alex.kanavin@gmail.com>
Date: Thu, 9 Jan 2020 13:22:46 +0100
Subject: [PATCH] test/regress_dns.c: patch out tests that require a working
@@ -14,10 +14,10 @@ Signed-off-by: Alexander Kanavin <alex.kanavin@gmail.com>
1 file changed, 4 deletions(-)
diff --git a/test/regress_dns.c b/test/regress_dns.c
-index d2084b7..a1a8f3b 100644
+index 9a8bff4..7449e94 100644
--- a/test/regress_dns.c
+++ b/test/regress_dns.c
-@@ -2394,8 +2394,6 @@ struct testcase_t dns_testcases[] = {
+@@ -2459,8 +2459,6 @@ struct testcase_t dns_testcases[] = {
{ "reissue_disable_when_inactive", dns_reissue_disable_when_inactive_test,
TT_FORK|TT_NEED_BASE|TT_NO_LOGS, &basic_setup, NULL },
{ "inflight", dns_inflight_test, TT_FORK|TT_NEED_BASE, &basic_setup, NULL },
@@ -26,7 +26,7 @@ index d2084b7..a1a8f3b 100644
#ifdef EVENT__HAVE_SETRLIMIT
{ "bufferevent_connect_hostname_emfile", test_bufferevent_connect_hostname,
TT_FORK|TT_NEED_BASE, &basic_setup, (char*)"emfile" },
-@@ -2405,8 +2403,6 @@ struct testcase_t dns_testcases[] = {
+@@ -2470,8 +2468,6 @@ struct testcase_t dns_testcases[] = {
{ "disable_when_inactive_no_ns", dns_disable_when_inactive_no_ns_test,
TT_FORK|TT_NEED_BASE|TT_NO_LOGS, &basic_setup, NULL },
diff --git a/meta/recipes-support/libevent/libevent/0002-test-regress.h-Increase-default-timeval-tolerance-50.patch b/meta/recipes-support/libevent/libevent/0002-test-regress.h-Increase-default-timeval-tolerance-50.patch
index 0b20eda3c08..effb825f315 100644
--- a/meta/recipes-support/libevent/libevent/0002-test-regress.h-Increase-default-timeval-tolerance-50.patch
+++ b/meta/recipes-support/libevent/libevent/0002-test-regress.h-Increase-default-timeval-tolerance-50.patch
@@ -1,4 +1,4 @@
-From dff8fd27edb23bc1486809186c6a4fe1f75f2179 Mon Sep 17 00:00:00 2001
+From 64f2b035a1073c9f594036b46521e19dac029ec2 Mon Sep 17 00:00:00 2001
From: Yi Fan Yu <yifan.yu@windriver.com>
Date: Thu, 22 Apr 2021 22:35:59 -0400
Subject: [PATCH] test/regress.h: Increase default timeval tolerance 50 ms ->
@@ -11,7 +11,7 @@ related tests in arm64 QEMU.
See: https://bugzilla.yoctoproject.org/show_bug.cgi?id=14163
(The root cause seems to be a heavy load)
-Upstream-Status: Submitted [https://github.com/libevent/libevent/pull/1157]
+Upstream-Status: Backport [https://github.com/libevent/libevent/pull/1157]
Signed-off-by: Yi Fan Yu <yifan.yu@windriver.com>
---
@@ -19,10 +19,10 @@ Signed-off-by: Yi Fan Yu <yifan.yu@windriver.com>
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/test/regress.h b/test/regress.h
-index f06a7669..829af4a7 100644
+index 43cb4ea..21cfb5f 100644
--- a/test/regress.h
+++ b/test/regress.h
-@@ -127,7 +127,7 @@ int test_ai_eq_(const struct evutil_addrinfo *ai, const char *sockaddr_port,
+@@ -123,7 +123,7 @@ int test_ai_eq_(const struct evutil_addrinfo *ai, const char *sockaddr_port,
tt_int_op(labs(timeval_msec_diff((tv1), (tv2)) - diff), <=, tolerance)
#define test_timeval_diff_eq(tv1, tv2, diff) \
@@ -30,4 +30,4 @@ index f06a7669..829af4a7 100644
+ test_timeval_diff_leq((tv1), (tv2), (diff), 100)
long timeval_msec_diff(const struct timeval *start, const struct timeval *end);
-
+
diff --git a/meta/recipes-support/libevent/libevent/0003-test-mark-util-monotonic_prc_fallback-as-retriable.patch b/meta/recipes-support/libevent/libevent/0003-test-mark-util-monotonic_prc_fallback-as-retriable.patch
index ddc19c495f1..aa0d4f9ef1b 100644
--- a/meta/recipes-support/libevent/libevent/0003-test-mark-util-monotonic_prc_fallback-as-retriable.patch
+++ b/meta/recipes-support/libevent/libevent/0003-test-mark-util-monotonic_prc_fallback-as-retriable.patch
@@ -1,20 +1,20 @@
-From d01a57a998798da977c470f3b8d6a457c1adb144 Mon Sep 17 00:00:00 2001
+From 9ad27391a97157eb8cee84a7e9cc3dc93df34cbb Mon Sep 17 00:00:00 2001
From: Azat Khuzhin <azat@libevent.org>
Date: Sun, 19 Sep 2021 00:57:31 +0300
Subject: [PATCH] test: mark util/monotonic_prc_fallback as retriable
Refs: #1193
-Upstream-Status: Backport
+Upstream-Status: Backport [https://github.com/libevent/libevent/commit/04fcd7c6df158bb65261867de4b9ec8439696934]
---
test/regress_util.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/test/regress_util.c b/test/regress_util.c
-index 45caa2700a40..a9e80db20149 100644
+index fd149b3..10244d6 100644
--- a/test/regress_util.c
+++ b/test/regress_util.c
-@@ -1672,7 +1672,7 @@ struct testcase_t util_testcases[] = {
+@@ -1674,7 +1674,7 @@ struct testcase_t util_testcases[] = {
{ "monotonic_res_fallback", test_evutil_monotonic_res, TT_OFF_BY_DEFAULT, &basic_setup, (void*)"fallback" },
{ "monotonic_prc", test_evutil_monotonic_prc, 0, &basic_setup, (void*)"" },
{ "monotonic_prc_precise", test_evutil_monotonic_prc, TT_RETRIABLE, &basic_setup, (void*)"precise" },
@@ -23,6 +23,3 @@ index 45caa2700a40..a9e80db20149 100644
{ "date_rfc1123", test_evutil_date_rfc1123, 0, NULL, NULL },
{ "evutil_v4addr_is_local", test_evutil_v4addr_is_local, 0, NULL, NULL },
{ "evutil_v6addr_is_local", test_evutil_v6addr_is_local, 0, NULL, NULL },
---
-2.31.1
-
diff --git a/meta/recipes-support/libevent/libevent/0004-test-retriable-tests-are-marked-failed-only-when-all-a.patch b/meta/recipes-support/libevent/libevent/0004-test-retriable-tests-are-marked-failed-only-when-all-a.patch
index 26b707ad316..4cb2a6d7bc0 100644
--- a/meta/recipes-support/libevent/libevent/0004-test-retriable-tests-are-marked-failed-only-when-all-a.patch
+++ b/meta/recipes-support/libevent/libevent/0004-test-retriable-tests-are-marked-failed-only-when-all-a.patch
@@ -1,4 +1,4 @@
-From 36ebd92fa53c0097f1e2f9ec5aa5b5c6ec1b411d Mon Sep 17 00:00:00 2001
+From 59ab048f0fe32fb8d8e43214f93c32b53148419c Mon Sep 17 00:00:00 2001
From: Thomas Perrot <thomas.perrot@bootlin.com>
Date: Wed, 29 Sep 2021 13:50:35 +0200
Subject: [PATCH] test: retriable tests are marked failed only when all
@@ -15,7 +15,7 @@ Signed-off-by: Thomas Perrot <thomas.perrot@bootlin.com>
2 files changed, 7 insertions(+), 8 deletions(-)
diff --git a/test/tinytest.c b/test/tinytest.c
-index 85dfe74a720e..bf2882418eb6 100644
+index 85dfe74..bf28824 100644
--- a/test/tinytest.c
+++ b/test/tinytest.c
@@ -310,7 +310,8 @@ testcase_run_forked_(const struct testgroup_t *group,
@@ -64,7 +64,7 @@ index 85dfe74a720e..bf2882418eb6 100644
switch (test_ret_err) {
diff --git a/test/tinytest.h b/test/tinytest.h
-index d321dd467542..c276b5339331 100644
+index d321dd4..c276b53 100644
--- a/test/tinytest.h
+++ b/test/tinytest.h
@@ -92,7 +92,7 @@ char *tinytest_format_hex_(const void *, unsigned long);
@@ -76,6 +76,3 @@ index d321dd467542..c276b5339331 100644
void tinytest_set_aliases(const struct testlist_alias_t *aliases);
---
-2.31.1
-
diff --git a/meta/recipes-support/libevent/libevent/Makefile-missing-test-dir.patch b/meta/recipes-support/libevent/libevent/Makefile-missing-test-dir.patch
index 8880bd04075..c54a2b7bb0f 100644
--- a/meta/recipes-support/libevent/libevent/Makefile-missing-test-dir.patch
+++ b/meta/recipes-support/libevent/libevent/Makefile-missing-test-dir.patch
@@ -1,4 +1,7 @@
-Fix missing test directory creation.
+From c16d91420b94701065d3bdfdf96c41e0710c3bc8 Mon Sep 17 00:00:00 2001
+From: Andrej Valek <andrej.valek@siemens.com>
+Date: Tue, 25 Apr 2017 08:11:48 +0200
+Subject: [PATCH] Fix missing test directory creation.
GCC used in OE-core has "dependency tracking" disabled and
libevent has problem with this.
@@ -12,12 +15,15 @@ Workaround specific to our build system.
Signed-off-by: Andrej Valek <andrej.valek@siemens.com>
Signed-off-by: Pascal Bach <pascal.bach@siemens.com>
+---
+ test/include.am | 1 +
+ 1 file changed, 1 insertion(+)
-diff --git a/libevent-2.1.8-stable/test/include.am b/libevent-2.1.8-stable/test/include.am
-index eea249f..d323dff 100644
+diff --git a/test/include.am b/test/include.am
+index 0437524..48c7307 100644
--- a/test/include.am
+++ b/test/include.am
-@@ -161,6 +161,7 @@ test_bench_httpclient_LDADD = $(LIBEVENT_GC_SECTIONS) libevent_core.la
+@@ -162,6 +162,7 @@ test_bench_httpclient_LDADD = $(LIBEVENT_GC_SECTIONS) libevent_core.la
test/regress.gen.c test/regress.gen.h: test/rpcgen-attempted
test/rpcgen-attempted: test/regress.rpc event_rpcgen.py test/rpcgen_wrapper.sh
diff --git a/meta/recipes-support/libevent/libevent_2.1.12.bb b/meta/recipes-support/libevent/libevent_2.1.13.bb
similarity index 95%
rename from meta/recipes-support/libevent/libevent_2.1.12.bb
rename to meta/recipes-support/libevent/libevent_2.1.13.bb
index 8bb6d90d705..431018f0f35 100644
--- a/meta/recipes-support/libevent/libevent_2.1.12.bb
+++ b/meta/recipes-support/libevent/libevent_2.1.13.bb
@@ -20,7 +20,7 @@ SRC_URI = "${GITHUB_BASE_URI}/download/release-${PV}-stable/${BP}-stable.tar.gz
file://0004-test-retriable-tests-are-marked-failed-only-when-all-a.patch \
"
-SRC_URI[sha256sum] = "92e6de1be9ec176428fd2367677e61ceffc2ee1cb119035037a27d346b0403bb"
+SRC_URI[sha256sum] = "f7e9383b8c0baa81b687e5b5eecc01beefaf1b19b64151d95ed61647fe7a315c"
UPSTREAM_CHECK_REGEX = "releases/tag/release-(?P<pver>.+)-stable"
S = "${UNPACKDIR}/${BPN}-${PV}-stable"
^ permalink raw reply related [flat|nested] 41+ messages in thread
* [OE-core][wrynose 20/40] libevent: set status for CVE-2026-63380
2026-09-05 20:44 [OE-core][wrynose 00/40] Patch review Yoann Congal
` (18 preceding siblings ...)
2026-09-05 20:44 ` [OE-core][wrynose 19/40] libevent: upgrade 2.1.12 -> 2.1.13 Yoann Congal
@ 2026-09-05 20:44 ` Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 21/40] libxfont2: Fix CVE-2026-56001 Yoann Congal
` (19 subsequent siblings)
39 siblings, 0 replies; 41+ messages in thread
From: Yoann Congal @ 2026-09-05 20:44 UTC (permalink / raw)
To: openembedded-core
From: Peter Marko <peter.marko@siemens.com>
Per [1] this only affects 2.2.1-alpha.
Also [2] markes their versions as not-affected.
[1] https://github.com/libevent/libevent/security/advisories/GHSA-3rpf-frgx-xq34
[2] https://security-tracker.debian.org/tracker/CVE-2026-63380
Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
meta/recipes-support/libevent/libevent_2.1.13.bb | 2 ++
1 file changed, 2 insertions(+)
diff --git a/meta/recipes-support/libevent/libevent_2.1.13.bb b/meta/recipes-support/libevent/libevent_2.1.13.bb
index 431018f0f35..222d4fd5b3c 100644
--- a/meta/recipes-support/libevent/libevent_2.1.13.bb
+++ b/meta/recipes-support/libevent/libevent_2.1.13.bb
@@ -55,3 +55,5 @@ do_install_ptest() {
# handle multilib
sed -i s:@libdir@:${libdir}:g ${D}${PTEST_PATH}/run-ptest
}
+
+CVE_STATUS[CVE-2026-63380] = "fixed-version: only affects 2.2.1-alpha"
^ permalink raw reply related [flat|nested] 41+ messages in thread
* [OE-core][wrynose 21/40] libxfont2: Fix CVE-2026-56001
2026-09-05 20:44 [OE-core][wrynose 00/40] Patch review Yoann Congal
` (19 preceding siblings ...)
2026-09-05 20:44 ` [OE-core][wrynose 20/40] libevent: set status for CVE-2026-63380 Yoann Congal
@ 2026-09-05 20:44 ` Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 22/40] libxfont2: Fix CVE-2026-56002 Yoann Congal
` (18 subsequent siblings)
39 siblings, 0 replies; 41+ messages in thread
From: Yoann Congal @ 2026-09-05 20:44 UTC (permalink / raw)
To: openembedded-core
From: Vijay Anusuri <vanusuri@mvista.com>
Pick patch according to [2]
[1] https://nvd.nist.gov/vuln/detail/CVE-2026-56001
[2] https://security-tracker.debian.org/tracker/CVE-2026-56001
Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../xorg-lib/libxfont2/CVE-2026-56001.patch | 75 +++++++++++++++++++
.../xorg-lib/libxfont2_2.0.7.bb | 3 +
2 files changed, 78 insertions(+)
create mode 100644 meta/recipes-graphics/xorg-lib/libxfont2/CVE-2026-56001.patch
diff --git a/meta/recipes-graphics/xorg-lib/libxfont2/CVE-2026-56001.patch b/meta/recipes-graphics/xorg-lib/libxfont2/CVE-2026-56001.patch
new file mode 100644
index 00000000000..58a1881442c
--- /dev/null
+++ b/meta/recipes-graphics/xorg-lib/libxfont2/CVE-2026-56001.patch
@@ -0,0 +1,75 @@
+From be0b08e2d354138d3222b4490e2a77c6ee42f778 Mon Sep 17 00:00:00 2001
+From: Peter Hutterer <peter.hutterer@who-t.net>
+Date: Mon, 1 Jun 2026 16:46:10 +1000
+Subject: [PATCH] bitscale: fix integer overflow in BitmapScaleBitmaps
+ bytestoalloc
+
+bytestoalloc is declared as unsigned int (32-bit). When the sum of
+per-glyph byte counts exceeds 2^32, the value wraps around and calloc()
+allocates a buffer that is too small. The subsequent ScaleBitmap loop
+then writes past the end of the allocated buffer.
+
+Change bytestoalloc from unsigned int to size_t to match the actual
+allocation size type, and add an explicit overflow check in the
+accumulation loop to bail out if the total would exceed SIZE_MAX.
+
+This vulnerability was discovered by:
+Anonymous working with TrendAI Zero Day Initiative
+
+CVE-2026-56001/ZDI-CAN-30558
+
+Assisted-by: Claude:claude-opus-4-6
+Signed-off-by: Peter Hutterer <peter.hutterer@who-t.net>
+Part-of: <https://gitlab.freedesktop.org/xorg/lib/libxfont/-/merge_requests/34>
+
+Upstream-Status: Backport [https://gitlab.freedesktop.org/xorg/lib/libxfont/-/commit/be0b08e2d354138d3222b4490e2a77c6ee42f778]
+CVE: CVE-2026-56001
+Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
+---
+ src/bitmap/bitscale.c | 23 ++++++++++++++++++++---
+ 1 file changed, 20 insertions(+), 3 deletions(-)
+
+diff --git a/src/bitmap/bitscale.c b/src/bitmap/bitscale.c
+index 3f3c10e..5f465d1 100644
+--- a/src/bitmap/bitscale.c
++++ b/src/bitmap/bitscale.c
+@@ -1456,7 +1456,7 @@ BitmapScaleBitmaps(FontPtr pf, /* scaled font */
+ opci;
+ FontInfoPtr pfi;
+ int glyph;
+- unsigned bytestoalloc = 0;
++ size_t bytestoalloc = 0;
+ int firstCol, lastCol, firstRow, lastRow;
+
+ double xform[4], inv_xform[4];
+@@ -1483,8 +1483,25 @@ BitmapScaleBitmaps(FontPtr pf, /* scaled font */
+ glyph = pf->glyph;
+ for (i = 0; i < nchars; i++)
+ {
+- if ((pci = ACCESSENCODING(bitmapFont->encoding, i)))
+- bytestoalloc += BYTES_FOR_GLYPH(pci, glyph);
++ if ((pci = ACCESSENCODING(bitmapFont->encoding, i))) {
++ size_t glyphsize = BYTES_FOR_GLYPH(pci, glyph);
++ if (bytestoalloc > SIZE_MAX - glyphsize) {
++ fprintf(stderr,
++ "Error: bitmap allocation overflow for scaled font\n");
++ goto bail;
++ }
++ bytestoalloc += glyphsize;
++ }
++ }
++
++ /* Reject unreasonably large bitmap allocations that could result
++ * from malicious fonts with extreme scale factors. 256 MiB is
++ * far beyond any legitimate scaled bitmap font. */
++#define BITMAP_SCALE_MAX_ALLOC (256 * 1024 * 1024)
++ if (bytestoalloc > BITMAP_SCALE_MAX_ALLOC) {
++ fprintf(stderr,
++ "Error: scaled bitmap size %zu exceeds limit\n", bytestoalloc);
++ goto bail;
+ }
+
+ /* Do we add the font malloc stuff for VALUE ADDED ? */
+--
+GitLab
+
diff --git a/meta/recipes-graphics/xorg-lib/libxfont2_2.0.7.bb b/meta/recipes-graphics/xorg-lib/libxfont2_2.0.7.bb
index bf49d728b92..bc6990576fd 100644
--- a/meta/recipes-graphics/xorg-lib/libxfont2_2.0.7.bb
+++ b/meta/recipes-graphics/xorg-lib/libxfont2_2.0.7.bb
@@ -15,6 +15,9 @@ XORG_PN = "libXfont2"
BBCLASSEXTEND = "native"
+SRC_URI += "file://CVE-2026-56001.patch \
+ "
+
SRC_URI[sha256sum] = "8b7b82fdeba48769b69433e8e3fbb984a5f6bf368b0d5f47abeec49de3e58efb"
PACKAGECONFIG ??= "${@bb.utils.filter('DISTRO_FEATURES', 'ipv6', d)}"
^ permalink raw reply related [flat|nested] 41+ messages in thread
* [OE-core][wrynose 22/40] libxfont2: Fix CVE-2026-56002
2026-09-05 20:44 [OE-core][wrynose 00/40] Patch review Yoann Congal
` (20 preceding siblings ...)
2026-09-05 20:44 ` [OE-core][wrynose 21/40] libxfont2: Fix CVE-2026-56001 Yoann Congal
@ 2026-09-05 20:44 ` Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 23/40] libxfont2: Fix CVE-2026-56003 Yoann Congal
` (17 subsequent siblings)
39 siblings, 0 replies; 41+ messages in thread
From: Yoann Congal @ 2026-09-05 20:44 UTC (permalink / raw)
To: openembedded-core
From: Vijay Anusuri <vanusuri@mvista.com>
Pick patch according to [2]
[1] https://nvd.nist.gov/vuln/detail/CVE-2026-56002
[2] https://security-tracker.debian.org/tracker/CVE-2026-56002
Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../xorg-lib/libxfont2/CVE-2026-56002.patch | 138 ++++++++++++++++++
.../xorg-lib/libxfont2_2.0.7.bb | 1 +
2 files changed, 139 insertions(+)
create mode 100644 meta/recipes-graphics/xorg-lib/libxfont2/CVE-2026-56002.patch
diff --git a/meta/recipes-graphics/xorg-lib/libxfont2/CVE-2026-56002.patch b/meta/recipes-graphics/xorg-lib/libxfont2/CVE-2026-56002.patch
new file mode 100644
index 00000000000..b2874c7c775
--- /dev/null
+++ b/meta/recipes-graphics/xorg-lib/libxfont2/CVE-2026-56002.patch
@@ -0,0 +1,138 @@
+From b4389e0b1d84a690b819bb27b1439968811a3674 Mon Sep 17 00:00:00 2001
+From: Peter Hutterer <peter.hutterer@who-t.net>
+Date: Mon, 1 Jun 2026 16:48:40 +1000
+Subject: [PATCH] pcfread: validate bitmap sizes and offsets against per-glyph
+ metrics
+
+pcfReadFont() uses bitmapSizes[] read directly from the PCF file to
+allocate the repadded bitmap buffer. However, per-glyph metrics (also
+from the file) control how much data RepadBitmap() writes. A malicious
+PCF font can declare a small bitmapSizes[] value while having per-glyph
+metrics that require more space, causing a heap buffer overflow.
+
+A similar issue happens with the encoding offsets: pcfReadFont reads
+encoding offsets from the PCF file and uses them to index into the
+metrics array without bounds checking. A crafted font can set an
+encoding offset larger than nmetrics, causing an out-of-bounds pointer
+that is later dereferenced when glyphs are accessed through the encoding
+table.
+
+And the no-repad bitmap path (when PCF_GLYPH_PAD matches the requested
+glyph pad) only validated that each glyph's offset was within the bitmap
+buffer, but did not check that the full glyph extent (offset +
+BYTES_PER_ROW * height) fits within the buffer. A crafted font with a
+glyph offset near the end of a small bitmap buffer but large glyph
+metrics causes a heap buffer over-read when the glyph is later rendered.
+
+This vulnerability was discovered by:
+ Anonymous working with TrendAI Zero Day Initiative
+
+CVE-2026-56002/ZDI-CAN-30559
+
+Assisted-by: Claude:claude-opus-4-6
+Signed-off-by: Peter Hutterer <peter.hutterer@who-t.net>
+Part-of: <https://gitlab.freedesktop.org/xorg/lib/libxfont/-/merge_requests/34>
+
+Upstream-Status: Backport [https://gitlab.freedesktop.org/xorg/lib/libxfont/-/commit/b4389e0b1d84a690b819bb27b1439968811a3674]
+CVE: CVE-2026-56002
+Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
+---
+ src/bitmap/pcfread.c | 59 +++++++++++++++++++++++++++++++++++++++++---
+ 1 file changed, 56 insertions(+), 3 deletions(-)
+
+diff --git a/src/bitmap/pcfread.c b/src/bitmap/pcfread.c
+index 7c2e7e1..a385331 100644
+--- a/src/bitmap/pcfread.c
++++ b/src/bitmap/pcfread.c
+@@ -532,25 +532,74 @@ pcfReadFont(FontPtr pFont, FontFilePtr file,
+ int old,
+ new;
+ xCharInfo *metric;
++ int srcPad = PCF_GLYPH_PAD(format);
+
+- sizepadbitmaps = bitmapSizes[PCF_SIZE_TO_INDEX(glyph)];
+- padbitmaps = malloc(sizepadbitmaps);
++ /* Compute the actual required size from per-glyph metrics instead
++ * of trusting the file's bitmapSizes[] value, which may be smaller
++ * than the actual data written by RepadBitmap. */
++ sizepadbitmaps = 0;
++ for (i = 0; i < nbitmaps; i++) {
++ int w, h, glyphBytes;
++ metric = &metrics[i].metrics;
++ w = metric->rightSideBearing - metric->leftSideBearing;
++ h = metric->ascent + metric->descent;
++ glyphBytes = BYTES_PER_ROW(w, glyph) * h;
++ if (glyphBytes < 0 || (glyphBytes > 0 && sizepadbitmaps > INT_MAX - glyphBytes)) {
++ pcfError("pcfReadFont(): bitmap size overflow\n");
++ goto Bail;
++ }
++ sizepadbitmaps += glyphBytes;
++ }
++ padbitmaps = malloc(sizepadbitmaps ? sizepadbitmaps : 1);
+ if (!padbitmaps) {
+ pcfError("pcfReadFont(): Couldn't allocate padbitmaps (%d)\n", sizepadbitmaps);
+ goto Bail;
+ }
+ new = 0;
+ for (i = 0; i < nbitmaps; i++) {
++ int srcGlyphBytes;
++
+ old = offsets[i];
+ metric = &metrics[i].metrics;
++
++ /* Validate source offset and source glyph size against the
++ * source bitmap buffer to prevent out-of-bounds reads. */
++ srcGlyphBytes = BYTES_PER_ROW(
++ metric->rightSideBearing - metric->leftSideBearing,
++ srcPad) * (metric->ascent + metric->descent);
++ if (old < 0 || old > sizebitmaps ||
++ srcGlyphBytes < 0 || srcGlyphBytes > sizebitmaps - old) {
++ pcfError("pcfReadFont(): bitmap offset/size out of bounds\n");
++ free(padbitmaps);
++ goto Bail;
++ }
++
+ offsets[i] = new;
+ new += RepadBitmap(bitmaps + old, padbitmaps + new,
+- PCF_GLYPH_PAD(format), glyph,
++ srcPad, glyph,
+ metric->rightSideBearing - metric->leftSideBearing,
+ metric->ascent + metric->descent);
+ }
+ free(bitmaps);
+ bitmaps = padbitmaps;
++ } else {
++ /* Validate offsets and full glyph extents against bitmap buffer */
++ for (i = 0; i < nbitmaps; i++) {
++ int glyphBytes;
++ xCharInfo *metric = &metrics[i].metrics;
++
++ glyphBytes = BYTES_PER_ROW(
++ metric->rightSideBearing - metric->leftSideBearing,
++ glyph) * (metric->ascent + metric->descent);
++ if (offsets[i] >= (CARD32)sizebitmaps ||
++ glyphBytes < 0 ||
++ glyphBytes > sizebitmaps - (int)offsets[i]) {
++ pcfError("pcfReadFont(): bitmap offset/size out of bounds "
++ "(offset %u, size %d, total %d)\n",
++ offsets[i], glyphBytes, sizebitmaps);
++ goto Bail;
++ }
++ }
+ }
+ for (i = 0; i < nbitmaps; i++)
+ metrics[i].bits = bitmaps + offsets[i];
+@@ -625,6 +674,10 @@ pcfReadFont(FontPtr pFont, FontFilePtr file,
+ if (IS_EOF(file)) goto Bail;
+ if (encodingOffset == 0xFFFF) {
+ pFont->info.allExist = FALSE;
++ } else if (encodingOffset >= nmetrics) {
++ pcfError("pcfReadFont(): encoding offset %d out of range (nmetrics=%d)\n",
++ encodingOffset, nmetrics);
++ goto Bail;
+ } else {
+ if(!encoding[SEGMENT_MAJOR(i)]) {
+ encoding[SEGMENT_MAJOR(i)]=
+--
+GitLab
+
diff --git a/meta/recipes-graphics/xorg-lib/libxfont2_2.0.7.bb b/meta/recipes-graphics/xorg-lib/libxfont2_2.0.7.bb
index bc6990576fd..e004ac044c2 100644
--- a/meta/recipes-graphics/xorg-lib/libxfont2_2.0.7.bb
+++ b/meta/recipes-graphics/xorg-lib/libxfont2_2.0.7.bb
@@ -16,6 +16,7 @@ XORG_PN = "libXfont2"
BBCLASSEXTEND = "native"
SRC_URI += "file://CVE-2026-56001.patch \
+ file://CVE-2026-56002.patch \
"
SRC_URI[sha256sum] = "8b7b82fdeba48769b69433e8e3fbb984a5f6bf368b0d5f47abeec49de3e58efb"
^ permalink raw reply related [flat|nested] 41+ messages in thread
* [OE-core][wrynose 23/40] libxfont2: Fix CVE-2026-56003
2026-09-05 20:44 [OE-core][wrynose 00/40] Patch review Yoann Congal
` (21 preceding siblings ...)
2026-09-05 20:44 ` [OE-core][wrynose 22/40] libxfont2: Fix CVE-2026-56002 Yoann Congal
@ 2026-09-05 20:44 ` Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 24/40] util-linux: Fix CVE-2026-3184 Yoann Congal
` (16 subsequent siblings)
39 siblings, 0 replies; 41+ messages in thread
From: Yoann Congal @ 2026-09-05 20:44 UTC (permalink / raw)
To: openembedded-core
From: Vijay Anusuri <vanusuri@mvista.com>
Pick patch according to [2]
[1] https://nvd.nist.gov/vuln/detail/CVE-2026-56003
[2] https://security-tracker.debian.org/tracker/CVE-2026-56003
Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../xorg-lib/libxfont2/CVE-2026-56003.patch | 114 ++++++++++++++++++
.../xorg-lib/libxfont2_2.0.7.bb | 1 +
2 files changed, 115 insertions(+)
create mode 100644 meta/recipes-graphics/xorg-lib/libxfont2/CVE-2026-56003.patch
diff --git a/meta/recipes-graphics/xorg-lib/libxfont2/CVE-2026-56003.patch b/meta/recipes-graphics/xorg-lib/libxfont2/CVE-2026-56003.patch
new file mode 100644
index 00000000000..dacfa9d638b
--- /dev/null
+++ b/meta/recipes-graphics/xorg-lib/libxfont2/CVE-2026-56003.patch
@@ -0,0 +1,114 @@
+From dff957a5158da038a282a59a31fe736702732939 Mon Sep 17 00:00:00 2001
+From: Peter Hutterer <peter.hutterer@who-t.net>
+Date: Mon, 1 Jun 2026 16:49:55 +1000
+Subject: [PATCH] bitscale: add bounds check to computeProps for property
+ buffer
+
+ComputeScaledProperties allocates a fixed-size property buffer of 70
+slots. computeProps iterates the source font's properties and writes 1
+slot for unscaled properties or 2 slots for scaledX/scaledY properties,
+with no bounds check. A malicious font with many duplicate properties
+matching fontPropTable entries can overflow the allocated buffer.
+
+Fix this by passing the remaining buffer capacity to computeProps and
+checking it before each write. Properties that would exceed the buffer
+are silently skipped.
+
+The function is also restructured to handle the buffer writes for
+scaledX/scaledY inside the switch cases directly, rather than in a
+separate block after the switch. This makes the control flow clearer and
+ensures the bounds check covers all writes.
+
+This vulnerability was discovered by:
+Anonymous working with TrendAI Zero Day Initiative
+
+CVE-2026-56003/ZDI-CAN-30560
+
+Assisted-by: Claude:claude-opus-4-6
+Signed-off-by: Peter Hutterer <peter.hutterer@who-t.net>
+Part-of: <https://gitlab.freedesktop.org/xorg/lib/libxfont/-/merge_requests/34>
+
+Upstream-Status: Backport [https://gitlab.freedesktop.org/xorg/lib/libxfont/-/commit/dff957a5158da038a282a59a31fe736702732939]
+CVE: CVE-2026-56003
+Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
+---
+ src/bitmap/bitscale.c | 39 ++++++++++++++++++++-------------------
+ 1 file changed, 20 insertions(+), 19 deletions(-)
+
+diff --git a/src/bitmap/bitscale.c b/src/bitmap/bitscale.c
+index 5f465d1..ec57f55 100644
+--- a/src/bitmap/bitscale.c
++++ b/src/bitmap/bitscale.c
+@@ -507,7 +507,8 @@ static int
+ computeProps(FontPropPtr pf, char *wasStringProp,
+ FontPropPtr npf, char *isStringProp,
+ unsigned int nprops, double xfactor, double yfactor,
+- double sXfactor, double sYfactor)
++ double sXfactor, double sYfactor,
++ int maxprops)
+ {
+ int n;
+ int count;
+@@ -522,14 +523,26 @@ computeProps(FontPropPtr pf, char *wasStringProp,
+
+ switch (t->type) {
+ case scaledX:
+- npf->value = doround(xfactor * (double)pf->value);
+- rawfactor = sXfactor;
+- break;
+ case scaledY:
+- npf->value = doround(yfactor * (double)pf->value);
+- rawfactor = sYfactor;
++ if (count + 2 > maxprops)
++ continue;
++ npf->value = (t->type == scaledX)
++ ? doround(xfactor * (double)pf->value)
++ : doround(yfactor * (double)pf->value);
++ rawfactor = (t->type == scaledX) ? sXfactor : sYfactor;
++ npf->name = pf->name;
++ npf++;
++ count++;
++ npf->value = doround(rawfactor * (double)pf->value);
++ npf->name = rawFontPropTable[t - fontPropTable].atom;
++ npf++;
++ count++;
++ *isStringProp++ = *wasStringProp;
++ *isStringProp++ = *wasStringProp;
+ break;
+ case unscaled:
++ if (count + 1 > maxprops)
++ continue;
+ npf->value = pf->value;
+ npf->name = pf->name;
+ npf++;
+@@ -539,18 +552,6 @@ computeProps(FontPropPtr pf, char *wasStringProp,
+ default:
+ break;
+ }
+- if (t->type != unscaled)
+- {
+- npf->name = pf->name;
+- npf++;
+- count++;
+- npf->value = doround(rawfactor * (double)pf->value);
+- npf->name = rawFontPropTable[t - fontPropTable].atom;
+- npf++;
+- count++;
+- *isStringProp++ = *wasStringProp;
+- *isStringProp++ = *wasStringProp;
+- }
+ }
+ return count;
+ }
+@@ -667,7 +668,7 @@ ComputeScaledProperties(FontInfoPtr sourceFontInfo, /* the font to be scaled */
+ n = NPROPS;
+ n += computeProps(sourceFontInfo->props, sourceFontInfo->isStringProp,
+ fp, isStringProp, sourceFontInfo->nprops, dx, dy,
+- sdx, sdy);
++ sdx, sdy, nProps - NPROPS);
+ return n;
+ }
+
+--
+GitLab
+
diff --git a/meta/recipes-graphics/xorg-lib/libxfont2_2.0.7.bb b/meta/recipes-graphics/xorg-lib/libxfont2_2.0.7.bb
index e004ac044c2..de6418b11a5 100644
--- a/meta/recipes-graphics/xorg-lib/libxfont2_2.0.7.bb
+++ b/meta/recipes-graphics/xorg-lib/libxfont2_2.0.7.bb
@@ -17,6 +17,7 @@ BBCLASSEXTEND = "native"
SRC_URI += "file://CVE-2026-56001.patch \
file://CVE-2026-56002.patch \
+ file://CVE-2026-56003.patch \
"
SRC_URI[sha256sum] = "8b7b82fdeba48769b69433e8e3fbb984a5f6bf368b0d5f47abeec49de3e58efb"
^ permalink raw reply related [flat|nested] 41+ messages in thread
* [OE-core][wrynose 24/40] util-linux: Fix CVE-2026-3184
2026-09-05 20:44 [OE-core][wrynose 00/40] Patch review Yoann Congal
` (22 preceding siblings ...)
2026-09-05 20:44 ` [OE-core][wrynose 23/40] libxfont2: Fix CVE-2026-56003 Yoann Congal
@ 2026-09-05 20:44 ` Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 25/40] python3: upgrade 3.14.6 -> 3.14.7 Yoann Congal
` (15 subsequent siblings)
39 siblings, 0 replies; 41+ messages in thread
From: Yoann Congal @ 2026-09-05 20:44 UTC (permalink / raw)
To: openembedded-core
From: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
Reference:
[1] https://nvd.nist.gov/vuln/detail/CVE-2026-3184
[2] https://github.com/util-linux/util-linux/commit/8b29aeb081e297e48c4c1ac53d88ae07e1331984
Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
meta/recipes-core/util-linux/util-linux.inc | 1 +
.../util-linux/util-linux/CVE-2026-3184.patch | 61 +++++++++++++++++++
2 files changed, 62 insertions(+)
create mode 100644 meta/recipes-core/util-linux/util-linux/CVE-2026-3184.patch
diff --git a/meta/recipes-core/util-linux/util-linux.inc b/meta/recipes-core/util-linux/util-linux.inc
index aec8721ca32..fdc62acc748 100644
--- a/meta/recipes-core/util-linux/util-linux.inc
+++ b/meta/recipes-core/util-linux/util-linux.inc
@@ -20,6 +20,7 @@ SRC_URI = "${KERNELORG_MIRROR}/linux/utils/util-linux/v${MAJOR_VERSION}/util-lin
file://0001-lsfd-mkfds-foreign-sockets-skip-when-lacking-sock_di.patch \
file://0001-ts-kill-decode-use-RTMIN-from-kill-L-instead-of-hard.patch \
file://0001-tests-script-Disable-size-option-test.patch \
+ file://CVE-2026-3184.patch \
"
SRC_URI[sha256sum] = "f586e35d320ff537aab3ffeca37e9ecd482ccbe013590db4429a414d8aa6a728"
diff --git a/meta/recipes-core/util-linux/util-linux/CVE-2026-3184.patch b/meta/recipes-core/util-linux/util-linux/CVE-2026-3184.patch
new file mode 100644
index 00000000000..6dbfebe4b91
--- /dev/null
+++ b/meta/recipes-core/util-linux/util-linux/CVE-2026-3184.patch
@@ -0,0 +1,61 @@
+From 3fb64ddbffbc9442dca56eb6d4f263d525708b64 Mon Sep 17 00:00:00 2001
+From: Karel Zak <kzak@redhat.com>
+Date: Thu, 19 Feb 2026 12:20:28 +0100
+Subject: [PATCH] login: use original FQDN for PAM_RHOST
+
+When login -h <remotehost> is invoked, init_remote_info() strips the
+local domain suffix from the hostname (FQDN to short name) before
+storing it in cxt->hostname. This truncated value is then used for
+PAM_RHOST, which can bypass pam_access host deny rules that match on
+the FQDN.
+
+Preserve the original -h hostname in a new cmd_hostname field and use
+it for PAM_RHOST, while keeping the truncated hostname for utmp/wtmp
+and logging unchanged.
+
+Note, the real-world impact is low -- login -h is only used by legacy
+telnet/rlogin daemons, and exploitation requires FQDN-specific
+pam_access rules on a system still using these obsolete services.
+
+Reported-by: Asim Viladi Oglu Manizada <manizada@pm.me>
+Signed-off-by: Karel Zak <kzak@redhat.com>
+(cherry picked from commit 8b29aeb081e297e48c4c1ac53d88ae07e1331984)
+
+CVE: CVE-2026-3184
+Upstream-Status: Backport [https://github.com/util-linux/util-linux/commit/8b29aeb081e297e48c4c1ac53d88ae07e1331984]
+
+Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
+---
+ login-utils/login.c | 5 ++++-
+ 1 file changed, 4 insertions(+), 1 deletion(-)
+
+diff --git a/login-utils/login.c b/login-utils/login.c
+index 321f9d6ce..0c5c805aa 100644
+--- a/login-utils/login.c
++++ b/login-utils/login.c
+@@ -128,6 +128,7 @@ struct login_context {
+ char *thishost; /* this machine */
+ char *thisdomain; /* this machine's domain */
+ char *hostname; /* remote machine */
++ char *cmd_hostname; /* remote machine as specified on command line */
+ char hostaddress[16]; /* remote address */
+
+ pid_t pid;
+@@ -906,7 +907,7 @@ static pam_handle_t *init_loginpam(struct login_context *cxt)
+
+ /* hostname & tty are either set to NULL or their correct values,
+ * depending on how much we know. */
+- rc = pam_set_item(pamh, PAM_RHOST, cxt->hostname);
++ rc = pam_set_item(pamh, PAM_RHOST, cxt->cmd_hostname);
+ if (is_pam_failure(rc))
+ loginpam_err(pamh, rc);
+
+@@ -1249,6 +1250,8 @@ static void init_remote_info(struct login_context *cxt, char *remotehost)
+
+ get_thishost(cxt, &domain);
+
++ cxt->cmd_hostname = xstrdup(remotehost);
++
+ if (domain && (p = strchr(remotehost, '.')) &&
+ strcasecmp(p + 1, domain) == 0)
+ *p = '\0';
^ permalink raw reply related [flat|nested] 41+ messages in thread
* [OE-core][wrynose 25/40] python3: upgrade 3.14.6 -> 3.14.7
2026-09-05 20:44 [OE-core][wrynose 00/40] Patch review Yoann Congal
` (23 preceding siblings ...)
2026-09-05 20:44 ` [OE-core][wrynose 24/40] util-linux: Fix CVE-2026-3184 Yoann Congal
@ 2026-09-05 20:44 ` Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 26/40] volatile-binds: order systemd-timesyncd after /var/lib Yoann Congal
` (14 subsequent siblings)
39 siblings, 0 replies; 41+ messages in thread
From: Yoann Congal @ 2026-09-05 20:44 UTC (permalink / raw)
To: openembedded-core
From: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
Release notes: [1]
Removed patches included in this release.
Removed obsolete CVE_STATUS entries.
[1] https://docs.python.org/3/whatsnew/changelog.html#python-3-14-7-final
(From OE-Core rev: 1e7832f8de0a07a2c7c6e239b31b82d47ccb915c)
Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
...shebang-overflow-on-python-config.py.patch | 6 +-
...e-stdin-I-O-errors-same-way-as-maste.patch | 4 +-
...-use-prefix-value-from-build-configu.patch | 7 +-
...-qemu-wrapper-when-gathering-profile.patch | 9 +--
...est_sysconfig-for-posix_user-purelib.patch | 4 +-
.../0001-prefer-valid-entrypoints.patch | 2 +-
...g.py-use-platlibdir-also-for-purelib.patch | 4 +-
...le.py-correct-the-test-output-format.patch | 6 +-
.../python/python3/CVE-2026-11940.patch | 67 -------------------
.../python/python3/CVE-2026-11972.patch | 61 -----------------
.../python/python3/makerace.patch | 6 +-
.../python/python3/valid-dists.patch | 2 +-
.../{python3_3.14.6.bb => python3_3.14.7.bb} | 7 +-
13 files changed, 24 insertions(+), 161 deletions(-)
delete mode 100644 meta/recipes-devtools/python/python3/CVE-2026-11940.patch
delete mode 100644 meta/recipes-devtools/python/python3/CVE-2026-11972.patch
rename meta/recipes-devtools/python/{python3_3.14.6.bb => python3_3.14.7.bb} (98%)
diff --git a/meta/recipes-devtools/python/python3/0001-Avoid-shebang-overflow-on-python-config.py.patch b/meta/recipes-devtools/python/python3/0001-Avoid-shebang-overflow-on-python-config.py.patch
index c2106f94370..7a605383647 100644
--- a/meta/recipes-devtools/python/python3/0001-Avoid-shebang-overflow-on-python-config.py.patch
+++ b/meta/recipes-devtools/python/python3/0001-Avoid-shebang-overflow-on-python-config.py.patch
@@ -1,4 +1,4 @@
-From 6b111a328c1c57b1580d63894b2b5d337316f6d4 Mon Sep 17 00:00:00 2001
+From 3f2df0e1fce8c7425998dade00d084f1b101a982 Mon Sep 17 00:00:00 2001
From: Paulo Neves <ptsneves@gmail.com>
Date: Tue, 7 Jun 2022 16:16:41 +0200
Subject: [PATCH] Avoid shebang overflow on python-config.py
@@ -16,10 +16,10 @@ Upstream-Status: Denied [distribution]
1 file changed, 2 insertions(+)
diff --git a/Makefile.pre.in b/Makefile.pre.in
-index 9ec3a71..f7d5382 100644
+index e946018..345ed29 100644
--- a/Makefile.pre.in
+++ b/Makefile.pre.in
-@@ -2829,6 +2829,8 @@ python-config: $(srcdir)/Misc/python-config.in Misc/python-config.sh
+@@ -2835,6 +2835,8 @@ python-config: $(srcdir)/Misc/python-config.in Misc/python-config.sh
@ # Substitution happens here, as the completely-expanded BINDIR
@ # is not available in configure
sed -e "s,@EXENAME@,$(EXENAME)," < $(srcdir)/Misc/python-config.in >python-config.py
diff --git a/meta/recipes-devtools/python/python3/0001-Lib-pty.py-handle-stdin-I-O-errors-same-way-as-maste.patch b/meta/recipes-devtools/python/python3/0001-Lib-pty.py-handle-stdin-I-O-errors-same-way-as-maste.patch
index d9072a36f7b..532adfe69a9 100644
--- a/meta/recipes-devtools/python/python3/0001-Lib-pty.py-handle-stdin-I-O-errors-same-way-as-maste.patch
+++ b/meta/recipes-devtools/python/python3/0001-Lib-pty.py-handle-stdin-I-O-errors-same-way-as-maste.patch
@@ -1,4 +1,4 @@
-From 129ee75863081d9e3418acca3df1e47667f671ad Mon Sep 17 00:00:00 2001
+From 9cd44429215352eb2753e0fd8e25fef24f714006 Mon Sep 17 00:00:00 2001
From: Alexander Kanavin <alex@linutronix.de>
Date: Thu, 16 Sep 2021 16:35:37 +0200
Subject: [PATCH] Lib/pty.py: handle stdin I/O errors same way as master I/O
@@ -29,7 +29,7 @@ Signed-off-by: Alexander Kanavin <alex@linutronix.de>
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/Lib/pty.py b/Lib/pty.py
-index 1d97994..fa8821b 100644
+index 4b25ac3..d6aac07 100644
--- a/Lib/pty.py
+++ b/Lib/pty.py
@@ -149,7 +149,10 @@ def _copy(master_fd, master_read=_read, stdin_read=_read):
diff --git a/meta/recipes-devtools/python/python3/0001-Lib-sysconfig.py-use-prefix-value-from-build-configu.patch b/meta/recipes-devtools/python/python3/0001-Lib-sysconfig.py-use-prefix-value-from-build-configu.patch
index 285580195b4..60391e726bd 100644
--- a/meta/recipes-devtools/python/python3/0001-Lib-sysconfig.py-use-prefix-value-from-build-configu.patch
+++ b/meta/recipes-devtools/python/python3/0001-Lib-sysconfig.py-use-prefix-value-from-build-configu.patch
@@ -1,4 +1,4 @@
-From e3c6e770e73e1329958db0a73883e42b01763ae3 Mon Sep 17 00:00:00 2001
+From b5aad6a9b6c5add7a85861aed8aa030c1ad3d52f Mon Sep 17 00:00:00 2001
From: Alexander Kanavin <alex@linutronix.de>
Date: Fri, 17 Nov 2023 14:26:32 +0100
Subject: [PATCH] Lib/sysconfig.py: use prefix value from build configuration
@@ -18,7 +18,7 @@ Signed-off-by: Trevor Gamblin <tgamblin@baylibre.com>
1 file changed, 5 insertions(+), 5 deletions(-)
diff --git a/Lib/sysconfig/__init__.py b/Lib/sysconfig/__init__.py
-index 2ecbff222fe..cec54cb23dc 100644
+index 0a8bcc0..a2341f2 100644
--- a/Lib/sysconfig/__init__.py
+++ b/Lib/sysconfig/__init__.py
@@ -538,12 +538,12 @@ def _init_config_vars():
@@ -39,6 +39,3 @@ index 2ecbff222fe..cec54cb23dc 100644
_CONFIG_VARS['implementation'] = _get_implementation()
_CONFIG_VARS['implementation_lower'] = _get_implementation().lower()
_CONFIG_VARS['abiflags'] = abiflags
---
-2.51.0
-
diff --git a/meta/recipes-devtools/python/python3/0001-Makefile.pre-use-qemu-wrapper-when-gathering-profile.patch b/meta/recipes-devtools/python/python3/0001-Makefile.pre-use-qemu-wrapper-when-gathering-profile.patch
index e25797f57ec..c7f14cad1e0 100644
--- a/meta/recipes-devtools/python/python3/0001-Makefile.pre-use-qemu-wrapper-when-gathering-profile.patch
+++ b/meta/recipes-devtools/python/python3/0001-Makefile.pre-use-qemu-wrapper-when-gathering-profile.patch
@@ -1,4 +1,4 @@
-From e7a8a7385f561f214054cf95f0a22bfa064eee0b Mon Sep 17 00:00:00 2001
+From d6f77e3a934616d1f6c083b7144c50a32e08b70a Mon Sep 17 00:00:00 2001
From: Alexander Kanavin <alex.kanavin@gmail.com>
Date: Wed, 30 Jan 2019 12:41:04 +0100
Subject: [PATCH] Makefile.pre: use qemu wrapper when gathering profile data
@@ -15,10 +15,10 @@ Signed-off-by: Trevor Gamblin <tgamblin@baylibre.com>
1 file changed, 1 insertion(+), 2 deletions(-)
diff --git a/Makefile.pre.in b/Makefile.pre.in
-index 3bd4495f95b..8e8fc60bc76 100644
+index 526d500..a7e536d 100644
--- a/Makefile.pre.in
+++ b/Makefile.pre.in
-@@ -857,8 +857,7 @@ profile-run-stamp:
+@@ -861,8 +861,7 @@ profile-run-stamp:
# enabled.
$(MAKE) profile-gen-stamp
# Next, run the profile task to generate the profile information.
@@ -28,6 +28,3 @@ index 3bd4495f95b..8e8fc60bc76 100644
$(LLVM_PROF_MERGER)
# Remove profile generation binary since we are done with it.
$(MAKE) clean-retain-profile
---
-2.39.5
-
diff --git a/meta/recipes-devtools/python/python3/0001-Update-test_sysconfig-for-posix_user-purelib.patch b/meta/recipes-devtools/python/python3/0001-Update-test_sysconfig-for-posix_user-purelib.patch
index 6a62c6dc5b9..5509b7475a9 100644
--- a/meta/recipes-devtools/python/python3/0001-Update-test_sysconfig-for-posix_user-purelib.patch
+++ b/meta/recipes-devtools/python/python3/0001-Update-test_sysconfig-for-posix_user-purelib.patch
@@ -1,4 +1,4 @@
-From 5bf5aa6eae1fa3eed66893e51a1858ab481426b4 Mon Sep 17 00:00:00 2001
+From c608cb4b3c8c31f1aa25ad1264ff58733fb99769 Mon Sep 17 00:00:00 2001
From: Wentao Zhang <wentao.zhang@windriver.com>
Date: Mon, 20 Mar 2023 13:39:52 +0800
Subject: [PATCH] Update test_sysconfig for posix_user purelib
@@ -22,7 +22,7 @@ Signed-off-by: Wentao Zhang <wentao.zhang@windriver.com>
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/Lib/test/test_sysconfig.py b/Lib/test/test_sysconfig.py
-index 1ade492..4e94889 100644
+index 1fe4b68..383142a 100644
--- a/Lib/test/test_sysconfig.py
+++ b/Lib/test/test_sysconfig.py
@@ -434,7 +434,7 @@ class TestSysConfig(unittest.TestCase, VirtualEnvironmentMixin):
diff --git a/meta/recipes-devtools/python/python3/0001-prefer-valid-entrypoints.patch b/meta/recipes-devtools/python/python3/0001-prefer-valid-entrypoints.patch
index 1250dc9ff04..ae3698fac47 100644
--- a/meta/recipes-devtools/python/python3/0001-prefer-valid-entrypoints.patch
+++ b/meta/recipes-devtools/python/python3/0001-prefer-valid-entrypoints.patch
@@ -1,4 +1,4 @@
-From ef33ac27e3ac1b9cb159d7eec0ad1af120cd9dc1 Mon Sep 17 00:00:00 2001
+From 8d7fcf04c6513841c7985e64b746b1ef5de0c426 Mon Sep 17 00:00:00 2001
From: Ross Burton <ross.burton@arm.com>
Date: Fri, 17 Apr 2026 16:53:42 +0100
Subject: [PATCH] prefer valid entrypoints
diff --git a/meta/recipes-devtools/python/python3/0001-sysconfig.py-use-platlibdir-also-for-purelib.patch b/meta/recipes-devtools/python/python3/0001-sysconfig.py-use-platlibdir-also-for-purelib.patch
index b9c68a98d70..7807827d9aa 100644
--- a/meta/recipes-devtools/python/python3/0001-sysconfig.py-use-platlibdir-also-for-purelib.patch
+++ b/meta/recipes-devtools/python/python3/0001-sysconfig.py-use-platlibdir-also-for-purelib.patch
@@ -1,4 +1,4 @@
-From bbcb17dc1ed283f41c8cd94d39f70898f0c45583 Mon Sep 17 00:00:00 2001
+From c10d1b295a9fb93836830cce441da3f22e5c7cd7 Mon Sep 17 00:00:00 2001
From: Alexander Kanavin <alex@linutronix.de>
Date: Sun, 12 Sep 2021 21:44:36 +0200
Subject: [PATCH] sysconfig.py: use platlibdir also for purelib
@@ -13,7 +13,7 @@ Signed-off-by: Alexander Kanavin <alex@linutronix.de>
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/Lib/sysconfig/__init__.py b/Lib/sysconfig/__init__.py
-index 80aef34..f8e1c7d 100644
+index faf8273..0a8bcc0 100644
--- a/Lib/sysconfig/__init__.py
+++ b/Lib/sysconfig/__init__.py
@@ -29,7 +29,7 @@ _INSTALL_SCHEMES = {
diff --git a/meta/recipes-devtools/python/python3/0001-test_locale.py-correct-the-test-output-format.patch b/meta/recipes-devtools/python/python3/0001-test_locale.py-correct-the-test-output-format.patch
index 201271b0c07..a60d082e2f4 100644
--- a/meta/recipes-devtools/python/python3/0001-test_locale.py-correct-the-test-output-format.patch
+++ b/meta/recipes-devtools/python/python3/0001-test_locale.py-correct-the-test-output-format.patch
@@ -1,4 +1,4 @@
-From c1f3cf625c0f011060ddaa2a4096f6aa13dd1ee6 Mon Sep 17 00:00:00 2001
+From f0ac5b479b99bfb7f5e937a941b31a596f4caafc Mon Sep 17 00:00:00 2001
From: Mingli Yu <mingli.yu@windriver.com>
Date: Mon, 5 Aug 2019 15:57:39 +0800
Subject: [PATCH] test_locale.py: correct the test output format
@@ -31,10 +31,10 @@ Signed-off-by: Mingli Yu <mingli.yu@windriver.com>
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/Lib/test/test_locale.py b/Lib/test/test_locale.py
-index da4bd79..fd9e67d 100644
+index f918435..1910a43 100644
--- a/Lib/test/test_locale.py
+++ b/Lib/test/test_locale.py
-@@ -500,7 +500,7 @@ class TestRealLocales(unittest.TestCase):
+@@ -499,7 +499,7 @@ class TestRealLocales(unittest.TestCase):
self.skipTest('test needs Turkish locale')
loc = locale.getlocale(locale.LC_CTYPE)
if verbose:
diff --git a/meta/recipes-devtools/python/python3/CVE-2026-11940.patch b/meta/recipes-devtools/python/python3/CVE-2026-11940.patch
deleted file mode 100644
index 05a5802c396..00000000000
--- a/meta/recipes-devtools/python/python3/CVE-2026-11940.patch
+++ /dev/null
@@ -1,67 +0,0 @@
-From e24b4e95524fbe8cd0f46aa3292e8040f0e07c83 Mon Sep 17 00:00:00 2001
-From: "Miss Islington (bot)"
- <31488909+miss-islington@users.noreply.github.com>
-Date: Tue, 23 Jun 2026 15:58:47 +0200
-Subject: [PATCH 1/2] gh-151558: Fix symlink escape via `tarfile`
- hardlink-extraction fallback (GH-151559)
-
-CVE: CVE-2026-11940
-Upstream-Status: Backport [https://github.com/python/cpython/commit/27dd970bf6b17ebca7c8ed486a40ab043ed7af8f]
-
-Signed-off-by: Benjamin Robin <benjamin.robin@bootlin.com>
----
- Lib/tarfile.py | 3 +++
- Lib/test/test_tarfile.py | 24 ++++++++++++++++++++++++
- 2 files changed, 27 insertions(+)
-
-diff --git a/Lib/tarfile.py b/Lib/tarfile.py
-index e6734db24f64..63f23490e8a1 100644
---- a/Lib/tarfile.py
-+++ b/Lib/tarfile.py
-@@ -2782,6 +2782,9 @@ def makelink_with_filter(self, tarinfo, targetpath,
- "makelink_with_filter: if filter_function is not None, "
- + "extraction_root must also not be None")
- try:
-+ filter_function(
-+ unfiltered.replace(name=tarinfo.name, deep=False),
-+ extraction_root)
- filtered = filter_function(unfiltered, extraction_root)
- except _FILTER_ERRORS as cause:
- raise LinkFallbackError(tarinfo, unfiltered.name) from cause
-diff --git a/Lib/test/test_tarfile.py b/Lib/test/test_tarfile.py
-index d974c7d46ec1..0fc7413be8db 100644
---- a/Lib/test/test_tarfile.py
-+++ b/Lib/test/test_tarfile.py
-@@ -4344,6 +4344,30 @@ def test_sneaky_hardlink_fallback(self):
- self.expect_file("boom", symlink_to='../../link_here')
- self.expect_file("c", symlink_to='b')
-
-+ @symlink_test
-+ def test_sneaky_hardlink_fallback_deep(self):
-+ # (CVE-2026-11940)
-+ with ArchiveMaker() as arc:
-+ arc.add("a/b/s", symlink_to=os.path.join("..", "escape"))
-+ arc.add("s", hardlink_to=os.path.join("a", "b", "s"))
-+
-+ with self.check_context(arc.open(), 'data'):
-+ e = self.expect_exception(
-+ tarfile.LinkFallbackError,
-+ "link 's' would be extracted as a copy of "
-+ + "'a/b/s', which was rejected")
-+ self.assertIsInstance(e.__cause__,
-+ tarfile.LinkOutsideDestinationError)
-+
-+ for filter in 'tar', 'fully_trusted':
-+ with self.subTest(filter), self.check_context(arc.open(), filter):
-+ if not os_helper.can_symlink():
-+ self.expect_file("a/")
-+ self.expect_file("a/b/")
-+ else:
-+ self.expect_file("a/b/s", symlink_to=os.path.join('..', 'escape'))
-+ self.expect_file("s", symlink_to=os.path.join('..', 'escape'))
-+
- @symlink_test
- def test_exfiltration_via_symlink(self):
- # (CVE-2025-4138)
---
-2.54.0
diff --git a/meta/recipes-devtools/python/python3/CVE-2026-11972.patch b/meta/recipes-devtools/python/python3/CVE-2026-11972.patch
deleted file mode 100644
index 12a79754feb..00000000000
--- a/meta/recipes-devtools/python/python3/CVE-2026-11972.patch
+++ /dev/null
@@ -1,61 +0,0 @@
-From 2d256d4bfd654bdcaf2d96733799be73b8ff8f69 Mon Sep 17 00:00:00 2001
-From: Petr Viktorin <encukou@gmail.com>
-Date: Tue, 23 Jun 2026 15:13:30 +0200
-Subject: [PATCH 2/2] gh-151981: Make tarfile._Stream.seek break at EOF
- (GH-151982)
-
-Co-authored-by: Stan Ulbrych <stan@python.org>
-
-CVE: CVE-2026-11972
-Upstream-Status: Backport [https://github.com/python/cpython/commit/f50bf13566189c8d0ce5a814f33eff3d89951896]
-
-Signed-off-by: Benjamin Robin <benjamin.robin@bootlin.com>
----
- Lib/tarfile.py | 4 +++-
- Lib/test/test_tarfile.py | 16 ++++++++++++++++
- 2 files changed, 19 insertions(+), 1 deletion(-)
-
-diff --git a/Lib/tarfile.py b/Lib/tarfile.py
-index 63f23490e8a1..399f906efdff 100644
---- a/Lib/tarfile.py
-+++ b/Lib/tarfile.py
-@@ -524,7 +524,9 @@ def seek(self, pos=0):
- if pos - self.pos >= 0:
- blocks, remainder = divmod(pos - self.pos, self.bufsize)
- for i in range(blocks):
-- self.read(self.bufsize)
-+ data = self.read(self.bufsize)
-+ if not data:
-+ break
- self.read(remainder)
- else:
- raise StreamError("seeking backwards is not allowed")
-diff --git a/Lib/test/test_tarfile.py b/Lib/test/test_tarfile.py
-index 0fc7413be8db..045377d620cc 100644
---- a/Lib/test/test_tarfile.py
-+++ b/Lib/test/test_tarfile.py
-@@ -4786,6 +4786,22 @@ def valueerror_filter(tarinfo, path):
- with self.check_context(arc.open(errorlevel='boo!'), filtererror_filter):
- self.expect_exception(TypeError) # errorlevel is not int
-
-+ @support.subTests('format', [tarfile.GNU_FORMAT, tarfile.PAX_FORMAT])
-+ def test_getmembers_big_size(self, format):
-+ # gh-151981: A loop in seek() for streaming files tried to read the
-+ # declared number of blocks even at EOF
-+ tinfo = tarfile.TarInfo("huge-file")
-+ tinfo.size = 1 << 64
-+ bio = io.BytesIO()
-+ # Write header without data
-+ bio.write(tinfo.tobuf(format))
-+
-+ # Reset & try to get contents
-+ bio.seek(0)
-+ with tarfile.open(fileobj=bio, mode="r|") as tar:
-+ with self.assertRaises(tarfile.ReadError):
-+ tar.getmembers()
-+
-
- class OverwriteTests(archiver_tests.OverwriteTests, unittest.TestCase):
- testdir = os.path.join(TEMPDIR, "testoverwrite")
---
-2.54.0
diff --git a/meta/recipes-devtools/python/python3/makerace.patch b/meta/recipes-devtools/python/python3/makerace.patch
index b29ea56cc34..248a521118c 100644
--- a/meta/recipes-devtools/python/python3/makerace.patch
+++ b/meta/recipes-devtools/python/python3/makerace.patch
@@ -1,4 +1,4 @@
-From 2b458b4e1bcd57e3f135d3f0e715f64b98b27906 Mon Sep 17 00:00:00 2001
+From b41557f570ff4451c477669d6ca5bfacabe21c66 Mon Sep 17 00:00:00 2001
From: Richard Purdie <richard.purdie@linuxfoundation.org>
Date: Tue, 13 Jul 2021 23:19:29 +0100
Subject: [PATCH] python3: Fix make race
@@ -17,10 +17,10 @@ Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/Makefile.pre.in b/Makefile.pre.in
-index be1b9ea..9ec3a71 100644
+index a7e536d..e946018 100644
--- a/Makefile.pre.in
+++ b/Makefile.pre.in
-@@ -2735,7 +2735,7 @@ COMPILEALL_OPTS=-j0
+@@ -2741,7 +2741,7 @@ COMPILEALL_OPTS=-j0
TEST_MODULES=@TEST_MODULES@
.PHONY: libinstall
diff --git a/meta/recipes-devtools/python/python3/valid-dists.patch b/meta/recipes-devtools/python/python3/valid-dists.patch
index 38b6ebc5cb1..7fe18254e50 100644
--- a/meta/recipes-devtools/python/python3/valid-dists.patch
+++ b/meta/recipes-devtools/python/python3/valid-dists.patch
@@ -1,4 +1,4 @@
-From a65c29adc027b3615154cab73aaedd58a6aa23da Mon Sep 17 00:00:00 2001
+From 66874ce1a9f21b4b00dc85919734d58e6243ca29 Mon Sep 17 00:00:00 2001
From: "Jason R. Coombs" <jaraco@jaraco.com>
Date: Tue, 23 Jul 2024 08:36:16 -0400
Subject: [PATCH] Prioritize valid dists to invalid dists when retrieving by
diff --git a/meta/recipes-devtools/python/python3_3.14.6.bb b/meta/recipes-devtools/python/python3_3.14.7.bb
similarity index 98%
rename from meta/recipes-devtools/python/python3_3.14.6.bb
rename to meta/recipes-devtools/python/python3_3.14.7.bb
index 0a9e82d445f..b798f1c3697 100644
--- a/meta/recipes-devtools/python/python3_3.14.6.bb
+++ b/meta/recipes-devtools/python/python3_3.14.7.bb
@@ -35,14 +35,12 @@ SRC_URI = "http://www.python.org/ftp/python/${PV}/Python-${PV}.tar.xz \
file://0001-Skip-flaky-test_default_timeout-tests.patch \
file://0001-test_only_active_thread-skip-problematic-test.patch \
file://0001-prefer-valid-entrypoints.patch \
- file://CVE-2026-11940.patch \
- file://CVE-2026-11972.patch \
"
SRC_URI:append:class-native = " \
file://0001-Lib-sysconfig.py-use-prefix-value-from-build-configu.patch \
"
-SRC_URI[sha256sum] = "143b1dddefaec3bd2e21e3b839b34a2b7fb9842272883c576420d605e9f30c63"
+SRC_URI[sha256sum] = "3b48dac8fb59f62eaa67ac83c1eb12bda1b7a08406dd286e252c11a66be27f81"
# exclude pre-releases for both python 2.x and 3.x
UPSTREAM_CHECK_REGEX = "[Pp]ython-(?P<pver>\d+(\.\d+)+).tar"
@@ -532,5 +530,4 @@ py3_sysroot_cleanup () {
rm -rf ${SYSROOT_DESTDIR}${libdir}/python${PYTHON_MAJMIN}/test
}
-CVE_STATUS[CVE-2026-6019] = "cpe-stable-backport: backported to v3.14.5"
-CVE_STATUS[CVE-2026-7210] = "cpe-stable-backport: backported to v3.14.6"
+
^ permalink raw reply related [flat|nested] 41+ messages in thread
* [OE-core][wrynose 26/40] volatile-binds: order systemd-timesyncd after /var/lib
2026-09-05 20:44 [OE-core][wrynose 00/40] Patch review Yoann Congal
` (24 preceding siblings ...)
2026-09-05 20:44 ` [OE-core][wrynose 25/40] python3: upgrade 3.14.6 -> 3.14.7 Yoann Congal
@ 2026-09-05 20:44 ` Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 27/40] go: upgrade 1.26.5 -> 1.26.6 Yoann Congal
` (13 subsequent siblings)
39 siblings, 0 replies; 41+ messages in thread
From: Yoann Congal @ 2026-09-05 20:44 UTC (permalink / raw)
To: openembedded-core
From: Esa Jaaskela <esa.jaaskela@suomi24.fi>
systemd-timesyncd stores its clock file under /var/lib/systemd/timesync,
so it can fail to save state if it starts before the volatile /var/lib
is mounted. Add it to the Before= and WantedBy= entries already used for
systemd-random-seed.service.
(cherry picked from commit 1b8d8c25e46f1df7079545f4297496426fd9d371)
Signed-off-by: Esa Jaaskela <esa.jaaskela@suomi24.fi>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Signed-off-by: Patrick Vogelaar <patrick.vogelaar@belden.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
meta/recipes-core/volatile-binds/volatile-binds.bb | 9 +++++----
1 file changed, 5 insertions(+), 4 deletions(-)
diff --git a/meta/recipes-core/volatile-binds/volatile-binds.bb b/meta/recipes-core/volatile-binds/volatile-binds.bb
index 857bcc93ff1..613e750c17c 100644
--- a/meta/recipes-core/volatile-binds/volatile-binds.bb
+++ b/meta/recipes-core/volatile-binds/volatile-binds.bb
@@ -57,10 +57,11 @@ ${@d.getVar('VOLATILE_BINDS').replace("\\n", "\n")}
END
if [ -e "$var_lib_servicefile" ]; then
- # As the seed is stored under /var/lib, ensure that this service runs
- # after the volatile /var/lib is mounted.
- sed -i -e "/^Before=/s/\$/ systemd-random-seed.service/" \
- -e "/^WantedBy=/s/\$/ systemd-random-seed.service/" \
+ # The random seed and the timesyncd clock file are stored under
+ # /var/lib, so ensure that those services run after the volatile
+ # /var/lib is mounted.
+ sed -i -e "/^Before=/s/\$/ systemd-random-seed.service systemd-timesyncd.service/" \
+ -e "/^WantedBy=/s/\$/ systemd-random-seed.service systemd-timesyncd.service/" \
"$var_lib_servicefile"
fi
}
^ permalink raw reply related [flat|nested] 41+ messages in thread
* [OE-core][wrynose 27/40] go: upgrade 1.26.5 -> 1.26.6
2026-09-05 20:44 [OE-core][wrynose 00/40] Patch review Yoann Congal
` (25 preceding siblings ...)
2026-09-05 20:44 ` [OE-core][wrynose 26/40] volatile-binds: order systemd-timesyncd after /var/lib Yoann Congal
@ 2026-09-05 20:44 ` Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 28/40] python3: add missing pyc files to core Yoann Congal
` (12 subsequent siblings)
39 siblings, 0 replies; 41+ messages in thread
From: Yoann Congal @ 2026-09-05 20:44 UTC (permalink / raw)
To: openembedded-core
From: Peter Marko <peter.marko@siemens.com>
Upgrade to latest 1.26.x release [1]:
$ git --no-pager log --oneline go1.26.5..go1.26.6
1ea5a71ad8 (tag: go1.26.6) [release-branch.go1.26] go1.26.6
115eb476aa [release-branch.go1.26] cmd/vendor: fix CVE-2026-56865 in x/mod
9f6980fd5c [release-branch.go1.26] cmd/vendor: fix CVE-2026-56864 in x/mod
6ec908dd24 [release-branch.go1.26] encoding/asn1: enforce maximum recursion depth
9918f26ab3 [release-branch.go1.26] encoding/xml: fix depth processing in (*Decoder).unmarshal
33ecb966ca [release-branch.go1.26] html/template: fix JavaScript regexp tracking
128893dbf9 [release-branch.go1.26] net/url: avoid quadratic complexity in resolvePath
13c194062c [release-branch.go1.26] cmd/compile: do not elide riscv64 sign extension of unsigned values
52e5e2f22a [release-branch.go1.26] cmd/compile: fix time traveling proofs in prove
db38ee7121 [release-branch.go1.26] cmd/compile: fix prove to generate Const64 for 64bits slicemasks
f5bf46f361 [release-branch.go1.26] cmd/compile: fix mips64le bigger than 32bits pointer offsets
f8d4fa6213 [release-branch.go1.26] runtime: fix frame pointer adjustment around injected calls
efc79671b1 [release-branch.go1.26] cmd/compile: do not home mul/div results in HI/LO
605fd48711 [release-branch.go1.26] crypto/tls: add fips140ems GODEBUG setting to disable EMS enforcement
100fb8f023 [release-branch.go1.26] cmd/link: quote PE .def library name
4d522f275f [release-branch.go1.26] cmd/compile: tighten mergelocals address use analysis
0e8a244fe5 [release-branch.go1.26] all: update x/net
019fcb0152 [release-branch.go1.26] cmd/compile: don't require Heapaddr for heap vars in dead code
b6432317a1 [release-branch.go1.26] crypto/tls: do not count handshake messages as state-advancing post-handshake
ae63e27897 [release-branch.go1.26] runtime: fix uninitialized 7th argument in mach_vm_region_trampoline
88bf57924f [release-branch.go1.26] runtime: don't emit write barrier for code pointers in itabInit
4238449188 [release-branch.go1.26] os: strip trailing slashes in RemoveAll on Plan 9
28f27d64cf [release-branch.go1.26] os: properly handle trailing / in Root.MkdirAll
cc312256f8 [release-branch.go1.26] runtime: be sure to scan small frame introduced by (*sigctxt).pushCall
07a0bbba1b [release-branch.go1.26] os: don't expect an error from Root.ReadFile from a directory on NetBSD
a42fec40ab [release-branch.go1.26] all: update x/net
5bbd22ff78 [release-branch.go1.26] net/http: apply header timeout to server's unencrypted HTTP/2 check
Fixes CVE-2026-56865, CVE-2026-56864, CVE-2026-56859, CVE-2026-56853,
CVE-2026-56860, CVE-2026-46600, CVE-2026-56862, CVE-2026-56858,
CVE-2026-39821 and CVE-2026-33818.
Release information: [2]
[1] https://github.com/golang/go/compare/go1.26.5...go1.26.6
[2] https://groups.google.com/g/golang-announce/c/94pEornpRlI
(From OE-Core rev: cae8a33abfda172e65166811eeb1bc7ad2d129a3)
Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
meta/recipes-devtools/go/{go-1.26.5.inc => go-1.26.6.inc} | 2 +-
...o-binary-native_1.26.5.bb => go-binary-native_1.26.6.bb} | 6 +++---
...cross-canadian_1.26.5.bb => go-cross-canadian_1.26.6.bb} | 0
.../go/{go-cross_1.26.5.bb => go-cross_1.26.6.bb} | 0
.../go/{go-crosssdk_1.26.5.bb => go-crosssdk_1.26.6.bb} | 0
.../go/{go-runtime_1.26.5.bb => go-runtime_1.26.6.bb} | 0
meta/recipes-devtools/go/{go_1.26.5.bb => go_1.26.6.bb} | 0
7 files changed, 4 insertions(+), 4 deletions(-)
rename meta/recipes-devtools/go/{go-1.26.5.inc => go-1.26.6.inc} (90%)
rename meta/recipes-devtools/go/{go-binary-native_1.26.5.bb => go-binary-native_1.26.6.bb} (80%)
rename meta/recipes-devtools/go/{go-cross-canadian_1.26.5.bb => go-cross-canadian_1.26.6.bb} (100%)
rename meta/recipes-devtools/go/{go-cross_1.26.5.bb => go-cross_1.26.6.bb} (100%)
rename meta/recipes-devtools/go/{go-crosssdk_1.26.5.bb => go-crosssdk_1.26.6.bb} (100%)
rename meta/recipes-devtools/go/{go-runtime_1.26.5.bb => go-runtime_1.26.6.bb} (100%)
rename meta/recipes-devtools/go/{go_1.26.5.bb => go_1.26.6.bb} (100%)
diff --git a/meta/recipes-devtools/go/go-1.26.5.inc b/meta/recipes-devtools/go/go-1.26.6.inc
similarity index 90%
rename from meta/recipes-devtools/go/go-1.26.5.inc
rename to meta/recipes-devtools/go/go-1.26.6.inc
index a4302b2790a..fa6b0a50a14 100644
--- a/meta/recipes-devtools/go/go-1.26.5.inc
+++ b/meta/recipes-devtools/go/go-1.26.6.inc
@@ -16,4 +16,4 @@ SRC_URI += "\
file://0009-go-Filter-build-paths-on-staticly-linked-arches.patch \
file://0010-cmd-go-clear-GOROOT-for-func-ldShared-when-trimpath-.patch \
"
-SRC_URI[main.sha256sum] = "495be4bc87176ac567392e5b4116abd98466d33d7b49d41e764ccc6976b2dc42"
+SRC_URI[main.sha256sum] = "a0721c54c688901448d77ad9b3ec7ea7c474730755ff891382e92ecb93ff2cb1"
diff --git a/meta/recipes-devtools/go/go-binary-native_1.26.5.bb b/meta/recipes-devtools/go/go-binary-native_1.26.6.bb
similarity index 80%
rename from meta/recipes-devtools/go/go-binary-native_1.26.5.bb
rename to meta/recipes-devtools/go/go-binary-native_1.26.6.bb
index 97a8270be2d..2913fb65151 100644
--- a/meta/recipes-devtools/go/go-binary-native_1.26.5.bb
+++ b/meta/recipes-devtools/go/go-binary-native_1.26.6.bb
@@ -9,9 +9,9 @@ PROVIDES = "go-native"
# Checksums available at https://go.dev/dl/
SRC_URI = "https://dl.google.com/go/go${PV}.${BUILD_GOOS}-${BUILD_GOARCH}.tar.gz;name=go_${BUILD_GOTUPLE}"
-SRC_URI[go_linux_amd64.sha256sum] = "5c2c3b16caefa1d968a94c1daca04a7ca301a496d9b086e17ad77bb81393f053"
-SRC_URI[go_linux_arm64.sha256sum] = "fe4789e92b1f33358680864bbe8704289e7bb5fc207d80623c308935bd696d49"
-SRC_URI[go_linux_ppc64le.sha256sum] = "c5d60e2b303bb612f20cd82786594b64874e73b35134025e27d3390bf284ae43"
+SRC_URI[go_linux_amd64.sha256sum] = "708effb774be8237570d0add163225abbdfaf4fca28b2611df167beba4feef89"
+SRC_URI[go_linux_arm64.sha256sum] = "d0507e9e9d7fe012aae570108cbd76c15de879e17130ab8cb90d4d7445cb1f2e"
+SRC_URI[go_linux_ppc64le.sha256sum] = "232b65543a42eda95df6a63f76235c1795bb535eba5c74e509faec71bc648388"
UPSTREAM_CHECK_URI = "https://golang.org/dl/"
UPSTREAM_CHECK_REGEX = "go(?P<pver>\d+(\.\d+)+)\.linux"
diff --git a/meta/recipes-devtools/go/go-cross-canadian_1.26.5.bb b/meta/recipes-devtools/go/go-cross-canadian_1.26.6.bb
similarity index 100%
rename from meta/recipes-devtools/go/go-cross-canadian_1.26.5.bb
rename to meta/recipes-devtools/go/go-cross-canadian_1.26.6.bb
diff --git a/meta/recipes-devtools/go/go-cross_1.26.5.bb b/meta/recipes-devtools/go/go-cross_1.26.6.bb
similarity index 100%
rename from meta/recipes-devtools/go/go-cross_1.26.5.bb
rename to meta/recipes-devtools/go/go-cross_1.26.6.bb
diff --git a/meta/recipes-devtools/go/go-crosssdk_1.26.5.bb b/meta/recipes-devtools/go/go-crosssdk_1.26.6.bb
similarity index 100%
rename from meta/recipes-devtools/go/go-crosssdk_1.26.5.bb
rename to meta/recipes-devtools/go/go-crosssdk_1.26.6.bb
diff --git a/meta/recipes-devtools/go/go-runtime_1.26.5.bb b/meta/recipes-devtools/go/go-runtime_1.26.6.bb
similarity index 100%
rename from meta/recipes-devtools/go/go-runtime_1.26.5.bb
rename to meta/recipes-devtools/go/go-runtime_1.26.6.bb
diff --git a/meta/recipes-devtools/go/go_1.26.5.bb b/meta/recipes-devtools/go/go_1.26.6.bb
similarity index 100%
rename from meta/recipes-devtools/go/go_1.26.5.bb
rename to meta/recipes-devtools/go/go_1.26.6.bb
^ permalink raw reply related [flat|nested] 41+ messages in thread
* [OE-core][wrynose 28/40] python3: add missing pyc files to core
2026-09-05 20:44 [OE-core][wrynose 00/40] Patch review Yoann Congal
` (26 preceding siblings ...)
2026-09-05 20:44 ` [OE-core][wrynose 27/40] go: upgrade 1.26.5 -> 1.26.6 Yoann Congal
@ 2026-09-05 20:44 ` Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 29/40] python3: fix stringold cache files Yoann Congal
` (11 subsequent siblings)
39 siblings, 0 replies; 41+ messages in thread
From: Yoann Congal @ 2026-09-05 20:44 UTC (permalink / raw)
To: openembedded-core
From: Tafil Avdyli <tafil@tafhub.de>
Recently _ast_unparse, _py_warnings and annotationlib were added to
core. The corresponding .pyc files were omitted, resulting them to be
generated on the target.
Fixes: 01982411b5cc ("python3: add _py_warnings, annotationlib to core")
Fixes: 9dfe1e7722fc ("python3: add _ast_unparse to core")
(cherry picked from commit 300a0ba0bc96b66be63f8c4324342ed1a9ef3c73)
Signed-off-by: Tafil Avdyli <tafil@tafhub.de>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Signed-off-by: Tafil Avdyli <tafil@tafhub.de>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
meta/recipes-devtools/python/python3/python3-manifest.json | 3 +++
1 file changed, 3 insertions(+)
diff --git a/meta/recipes-devtools/python/python3/python3-manifest.json b/meta/recipes-devtools/python/python3/python3-manifest.json
index 11ce2c97d2d..5d46e4e8b9b 100644
--- a/meta/recipes-devtools/python/python3/python3-manifest.json
+++ b/meta/recipes-devtools/python/python3/python3-manifest.json
@@ -324,16 +324,19 @@
],
"cached": [
"${libdir}/python${PYTHON_MAJMIN}/__pycache__/__future__.*.pyc",
+ "${libdir}/python${PYTHON_MAJMIN}/__pycache__/_ast_unparse.*.pyc",
"${libdir}/python${PYTHON_MAJMIN}/__pycache__/_bootlocale.*.pyc",
"${libdir}/python${PYTHON_MAJMIN}/__pycache__/_collections_abc.*.pyc",
"${libdir}/python${PYTHON_MAJMIN}/__pycache__/_colorize.*.pyc",
"${libdir}/python${PYTHON_MAJMIN}/__pycache__/_compression.*.pyc",
"${libdir}/python${PYTHON_MAJMIN}/__pycache__/_markupbase.*.pyc",
"${libdir}/python${PYTHON_MAJMIN}/__pycache__/_opcode_metadata.*.pyc",
+ "${libdir}/python${PYTHON_MAJMIN}/__pycache__/_py_warnings.*.pyc",
"${libdir}/python${PYTHON_MAJMIN}/__pycache__/_sitebuiltins.*.pyc",
"${libdir}/python${PYTHON_MAJMIN}/__pycache__/_sysconfigdata*.*.pyc",
"${libdir}/python${PYTHON_MAJMIN}/__pycache__/_weakrefset.*.pyc",
"${libdir}/python${PYTHON_MAJMIN}/__pycache__/abc.*.pyc",
+ "${libdir}/python${PYTHON_MAJMIN}/__pycache__/annotationlib.*.pyc",
"${libdir}/python${PYTHON_MAJMIN}/__pycache__/argparse.*.pyc",
"${libdir}/python${PYTHON_MAJMIN}/__pycache__/ast.*.pyc",
"${libdir}/python${PYTHON_MAJMIN}/__pycache__/bisect.*.pyc",
^ permalink raw reply related [flat|nested] 41+ messages in thread
* [OE-core][wrynose 29/40] python3: fix stringold cache files
2026-09-05 20:44 [OE-core][wrynose 00/40] Patch review Yoann Congal
` (27 preceding siblings ...)
2026-09-05 20:44 ` [OE-core][wrynose 28/40] python3: add missing pyc files to core Yoann Congal
@ 2026-09-05 20:44 ` Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 30/40] python3-git: fix CVE_PRODUCT Yoann Congal
` (10 subsequent siblings)
39 siblings, 0 replies; 41+ messages in thread
From: Yoann Congal @ 2026-09-05 20:44 UTC (permalink / raw)
To: openembedded-core
From: Tafil Avdyli <tafil@tafhub.de>
In the 3.14.0 upgrade the stringold package updated to the string module
directory but did not update the cache files. This resulted on targets
to generate `string/__pycache__/__init__.cpython-314.pyc`.
The packaging of the cache files can be only separated with a manual
edit but breaks do_create_manifest. Instead follow other packages and
bundle `string/__pycache__` in files.
Fixes: 56318067ab3e ("python3: upgrade 3.13.11 -> 3.14.0")
(cherry picked from commit 90e44d557d9897bd5c73018825d74eb338273b58)
Signed-off-by: Tafil Avdyli <tafil@tafhub.de>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Signed-off-by: Tafil Avdyli <tafil@tafhub.de>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../recipes-devtools/python/python3/python3-manifest.json | 8 +++-----
1 file changed, 3 insertions(+), 5 deletions(-)
diff --git a/meta/recipes-devtools/python/python3/python3-manifest.json b/meta/recipes-devtools/python/python3/python3-manifest.json
index 5d46e4e8b9b..008d41e5654 100644
--- a/meta/recipes-devtools/python/python3/python3-manifest.json
+++ b/meta/recipes-devtools/python/python3/python3-manifest.json
@@ -1047,12 +1047,10 @@
"core"
],
"files": [
- "${libdir}/python${PYTHON_MAJMIN}/string/__init__.py",
- "${libdir}/python${PYTHON_MAJMIN}/string/templatelib.py"
+ "${libdir}/python${PYTHON_MAJMIN}/string",
+ "${libdir}/python${PYTHON_MAJMIN}/string/__pycache__"
],
- "cached": [
- "${libdir}/python${PYTHON_MAJMIN}/__pycache__/string.*.pyc"
- ]
+ "cached": []
},
"syslog": {
"summary": "Python syslog interface",
^ permalink raw reply related [flat|nested] 41+ messages in thread
* [OE-core][wrynose 30/40] python3-git: fix CVE_PRODUCT
2026-09-05 20:44 [OE-core][wrynose 00/40] Patch review Yoann Congal
` (28 preceding siblings ...)
2026-09-05 20:44 ` [OE-core][wrynose 29/40] python3: fix stringold cache files Yoann Congal
@ 2026-09-05 20:44 ` Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 31/40] binutils: stable 2.46 branch updates Yoann Congal
` (9 subsequent siblings)
39 siblings, 0 replies; 41+ messages in thread
From: Yoann Congal @ 2026-09-05 20:44 UTC (permalink / raw)
To: openembedded-core
From: Tim Orling <tim.orling@konsulko.com>
Using the pypi.bbclass default CPE of python:GitPython detects no CVEs.
With CVE_PRODUCT = "gitpython_project:gitpython" we properly detect
9 CVEs, with 4 unpatched.
WARNING: core-image-full-cmdline-1.0-r0 do_sbom_cve_check:
python3-git-3.1.43: Found unpatched CVEs: CVE-2026-42215, CVE-2026-42284,
CVE-2026-44243, CVE-2026-44244
(cherry picked from commit 3a6af75a33b4e007f0d3a247b6a149e32d51e510)
Signed-off-by: Tim Orling <tim.orling@konsulko.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
meta/recipes-devtools/python/python3-git_3.1.43.bb | 2 ++
1 file changed, 2 insertions(+)
diff --git a/meta/recipes-devtools/python/python3-git_3.1.43.bb b/meta/recipes-devtools/python/python3-git_3.1.43.bb
index 7534531fa37..ebb5e4b442a 100644
--- a/meta/recipes-devtools/python/python3-git_3.1.43.bb
+++ b/meta/recipes-devtools/python/python3-git_3.1.43.bb
@@ -10,6 +10,8 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=5279a7ab369ba336989dcf2a107e5c8e"
PYPI_PACKAGE = "GitPython"
+CVE_PRODUCT = "gitpython_project:gitpython"
+
inherit pypi python_setuptools_build_meta
SRC_URI += "file://CVE-2026-42284.patch \
^ permalink raw reply related [flat|nested] 41+ messages in thread
* [OE-core][wrynose 31/40] binutils: stable 2.46 branch updates
2026-09-05 20:44 [OE-core][wrynose 00/40] Patch review Yoann Congal
` (29 preceding siblings ...)
2026-09-05 20:44 ` [OE-core][wrynose 30/40] python3-git: fix CVE_PRODUCT Yoann Congal
@ 2026-09-05 20:44 ` Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 32/40] python3-click: upgrade 8.3.1 -> 8.3.3 Yoann Congal
` (8 subsequent siblings)
39 siblings, 0 replies; 41+ messages in thread
From: Yoann Congal @ 2026-09-05 20:44 UTC (permalink / raw)
To: openembedded-core
From: Sowmya Sathram <sowmyasathram12@gmail.com>
Below commits from the binutils-2.46 stable branch are updated
on top of the 2.46.1 release.
046eeeef472 x86: Check XMM destination when optimizing 128-bit VPBROADCASTQ
2c77fbc7007 PR 34204 dlltool SEGVs with --exclude-symbols
38093d82a3e Re-enable development on the 2.46 branch
Test Results:
Before After Diff
No. of expected passes 327 327 0
No. of untested testcases 5 5 0
No. of unsupported tests 9 9 0
Signed-off-by: Sowmya Sathram <sowmyasathram12@gmail.com>
Signed-off-by: Hemanth Kumar M D <Hemanth.KumarMD@windriver.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
meta/recipes-devtools/binutils/binutils-2.46.inc | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/meta/recipes-devtools/binutils/binutils-2.46.inc b/meta/recipes-devtools/binutils/binutils-2.46.inc
index cae7c1c872e..f798d6f1a00 100644
--- a/meta/recipes-devtools/binutils/binutils-2.46.inc
+++ b/meta/recipes-devtools/binutils/binutils-2.46.inc
@@ -23,7 +23,7 @@ CVE_STATUS[CVE-2025-69651] = "disputed: observed behavior only in pre-release co
CVE_STATUS[CVE-2025-69649] = "fixed-version: Fixed from version 2.46"
CVE_STATUS[CVE-2025-69652] = "fixed-version: Fixed from version 2.46"
-SRCREV ?= "5e56594815854de5eca35c7c04b11705d0f19c02"
+SRCREV ?= "a9c090db342ac76f10bc47258ef8e58f7eaca748"
BINUTILS_GIT_URI ?= "git://sourceware.org/git/binutils-gdb.git;branch=${SRCBRANCH};protocol=https"
SRC_URI = "\
${BINUTILS_GIT_URI} \
^ permalink raw reply related [flat|nested] 41+ messages in thread
* [OE-core][wrynose 32/40] python3-click: upgrade 8.3.1 -> 8.3.3
2026-09-05 20:44 [OE-core][wrynose 00/40] Patch review Yoann Congal
` (30 preceding siblings ...)
2026-09-05 20:44 ` [OE-core][wrynose 31/40] binutils: stable 2.46 branch updates Yoann Congal
@ 2026-09-05 20:44 ` Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 33/40] python3-idna: Fix CVE-2026-45409 Yoann Congal
` (7 subsequent siblings)
39 siblings, 0 replies; 41+ messages in thread
From: Yoann Congal @ 2026-09-05 20:44 UTC (permalink / raw)
To: openembedded-core
From: Richard Purdie <richard.purdie@linuxfoundation.org>
Upgrade Click to 8.3.3, the first upstream release
containing the fix for CVE-2026-7246. The fix avoids
constructing an editor shell command and passes the editor
and filename as separate argv elements.
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit 002ede0d89b43cfbe15651ea6c3d504626be24df)
Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
[YC: Changelog: https://click.palletsprojects.com/en/stable/changes/#version-8-3-3 ]
---
.../python/{python3-click_8.3.1.bb => python3-click_8.3.3.bb} | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
rename meta/recipes-devtools/python/{python3-click_8.3.1.bb => python3-click_8.3.3.bb} (91%)
diff --git a/meta/recipes-devtools/python/python3-click_8.3.1.bb b/meta/recipes-devtools/python/python3-click_8.3.3.bb
similarity index 91%
rename from meta/recipes-devtools/python/python3-click_8.3.1.bb
rename to meta/recipes-devtools/python/python3-click_8.3.3.bb
index 49204e96e1f..9e80f8aff0f 100644
--- a/meta/recipes-devtools/python/python3-click_8.3.1.bb
+++ b/meta/recipes-devtools/python/python3-click_8.3.3.bb
@@ -8,7 +8,7 @@ HOMEPAGE = "http://click.pocoo.org/"
LICENSE = "BSD-3-Clause"
LIC_FILES_CHKSUM = "file://LICENSE.txt;md5=1fa98232fd645608937a0fdc82e999b8"
-SRC_URI[sha256sum] = "12ff4785d337a1bb490bb7e9c2b1ee5da3112e94a8622f26a6c77f5d2fc6842a"
+SRC_URI[sha256sum] = "398329ad4837b2ff7cbe1dd166a4c0f8900c3ca3a218de04466f38f6497f18a2"
inherit pypi python_flit_core ptest-python-pytest
^ permalink raw reply related [flat|nested] 41+ messages in thread
* [OE-core][wrynose 33/40] python3-idna: Fix CVE-2026-45409
2026-09-05 20:44 [OE-core][wrynose 00/40] Patch review Yoann Congal
` (31 preceding siblings ...)
2026-09-05 20:44 ` [OE-core][wrynose 32/40] python3-click: upgrade 8.3.1 -> 8.3.3 Yoann Congal
@ 2026-09-05 20:44 ` Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 34/40] perl: fix CVE-2026-42496 and CVE-2026-42497 Yoann Congal
` (6 subsequent siblings)
39 siblings, 0 replies; 41+ messages in thread
From: Yoann Congal @ 2026-09-05 20:44 UTC (permalink / raw)
To: openembedded-core
From: Hetvi Thakar <hthakar@cisco.com>
This patch applies the upstream 3.15 backport for
CVE-2026-45409. The upstream fix commit series is referenced
in [1], and the public CVE advisory is referenced in [2]. The
individual backported commit links are recorded in the embedded
patch headers.
Backport Changes:
- Omitted the first commit's HISTORY.rst release entry because it
conflicts with the 3.11 history and is not required for the fix.
[1] https://github.com/kjd/idna/compare/v3.13...v3.15
[2] https://github.com/advisories/GHSA-65pc-fj4g-8rjx
Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../python3-idna/CVE-2026-45409_p1.patch | 75 +++++++++++++++++++
.../python3-idna/CVE-2026-45409_p2.patch | 48 ++++++++++++
.../python3-idna/CVE-2026-45409_p3.patch | 72 ++++++++++++++++++
.../python/python3-idna_3.11.bb | 4 +
4 files changed, 199 insertions(+)
create mode 100644 meta/recipes-devtools/python/python3-idna/CVE-2026-45409_p1.patch
create mode 100644 meta/recipes-devtools/python/python3-idna/CVE-2026-45409_p2.patch
create mode 100644 meta/recipes-devtools/python/python3-idna/CVE-2026-45409_p3.patch
diff --git a/meta/recipes-devtools/python/python3-idna/CVE-2026-45409_p1.patch b/meta/recipes-devtools/python/python3-idna/CVE-2026-45409_p1.patch
new file mode 100644
index 00000000000..8c103635cf1
--- /dev/null
+++ b/meta/recipes-devtools/python/python3-idna/CVE-2026-45409_p1.patch
@@ -0,0 +1,75 @@
+From 6c647e3d5d9daca452ae74fc10d50f20e998e444 Mon Sep 17 00:00:00 2001
+From: Kim Davies <kim@cynosure.com.au>
+Date: Sun, 10 May 2026 08:47:22 -0700
+Subject: [PATCH] Merge commit from fork
+
+CVE: CVE-2026-45409
+Upstream-Status: Backport [https://github.com/kjd/idna/commit/c0dda4501df5d91c3181ce6f962dc5de74e82cc1]
+
+Backport Changes:
+- Omitted HISTORY.rst because its 3.14 release entry conflicts with the 3.11
+ history and is not required for the security fix.
+
+(cherry picked from commit c0dda4501df5d91c3181ce6f962dc5de74e82cc1)
+Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
+---
+ idna/core.py | 14 ++++++++++++++
+ tests/test_idna.py | 13 +++++++++++++
+ 2 files changed, 27 insertions(+)
+
+diff --git a/idna/core.py b/idna/core.py
+index 8177bf7..ce995c9 100644
+--- a/idna/core.py
++++ b/idna/core.py
+@@ -377,6 +377,15 @@ def encode(
+ raise IDNAError("should pass a unicode string to the function rather than a byte string.")
+ if uts46:
+ s = uts46_remap(s, std3_rules, transitional)
++
++ # Reject inputs that exceed the maximum DNS domain length up-front.
++ # Each codepoint in a U-label contributes at least one octet to its
++ # A-label form, so any input longer than the domain limit cannot
++ # produce a valid A-domain. Short-circuiting here prevents per-label
++ # validation from being driven into quadratic time
++ if len(s) > 254:
++ raise IDNAError("Domain too long")
++
+ trailing_dot = False
+ result = []
+ if strict:
+@@ -415,6 +424,11 @@ def decode(
+ raise IDNAError("Invalid ASCII in A-label")
+ if uts46:
+ s = uts46_remap(s, std3_rules, False)
++ # See encode() for rationale; the same bound applies because every
++ # legal A-domain is at most 254 octets and every codepoint of a
++ # legal U-domain contributes at least one octet to its A-form.
++ if len(s) > 254:
++ raise IDNAError("Domain too long")
+ trailing_dot = False
+ result = []
+ if not strict:
+diff --git a/tests/test_idna.py b/tests/test_idna.py
+index b59f5e5..ff24ebf 100755
+--- a/tests/test_idna.py
++++ b/tests/test_idna.py
+@@ -80,6 +80,19 @@ class IDNATests(unittest.TestCase):
+ self.assertFalse(idna.valid_label_length("a" * 64))
+ self.assertRaises(idna.IDNAError, idna.encode, "a" * 64)
+
++ def test_oversized_input_rejected_promptly(self):
++ # GHSA-65pc-fj4g-8rjx: encode/decode must reject inputs that
++ # exceed the maximum DNS domain length before per-codepoint
++ # validation runs, so labels dominated by CONTEXTO codepoints
++ # cannot drive validation into quadratic time.
++ import time
++
++ for payload in ("٠" * 8000, "・" * 8000 + "漢"):
++ start = time.perf_counter()
++ self.assertRaises(idna.IDNAError, idna.encode, payload)
++ self.assertRaises(idna.IDNAError, idna.decode, payload)
++ self.assertLess(time.perf_counter() - start, 1.0)
++
+ def test_check_bidi(self):
+ la = "\u0061"
+ r = "\u05d0"
diff --git a/meta/recipes-devtools/python/python3-idna/CVE-2026-45409_p2.patch b/meta/recipes-devtools/python/python3-idna/CVE-2026-45409_p2.patch
new file mode 100644
index 00000000000..07b5b148f58
--- /dev/null
+++ b/meta/recipes-devtools/python/python3-idna/CVE-2026-45409_p2.patch
@@ -0,0 +1,48 @@
+From 44713e1252442331fd49dfca00cd42bc27859198 Mon Sep 17 00:00:00 2001
+From: Kim Davies <kim@cynosure.com.au>
+Date: Sun, 10 May 2026 12:44:47 -0700
+Subject: [PATCH] Use valid_string_length() for early oversized-input check
+
+CVE: CVE-2026-45409
+Upstream-Status: Backport [https://github.com/kjd/idna/commit/628fef84d3eda59321c21127e73dcd873db23ead]
+
+(cherry picked from commit 628fef84d3eda59321c21127e73dcd873db23ead)
+Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
+---
+ idna/core.py | 16 ++++++----------
+ 1 file changed, 6 insertions(+), 10 deletions(-)
+
+diff --git a/idna/core.py b/idna/core.py
+index ce995c9..db19bda 100644
+--- a/idna/core.py
++++ b/idna/core.py
+@@ -378,12 +378,9 @@ def encode(
+ if uts46:
+ s = uts46_remap(s, std3_rules, transitional)
+
+- # Reject inputs that exceed the maximum DNS domain length up-front.
+- # Each codepoint in a U-label contributes at least one octet to its
+- # A-label form, so any input longer than the domain limit cannot
+- # produce a valid A-domain. Short-circuiting here prevents per-label
+- # validation from being driven into quadratic time
+- if len(s) > 254:
++ # Reject inputs that exceed the maximum DNS domain length up-front
++ # to avoid expensive computation on long inputs.
++ if not valid_string_length(s, trailing_dot=True):
+ raise IDNAError("Domain too long")
+
+ trailing_dot = False
+@@ -424,10 +421,9 @@ def decode(
+ raise IDNAError("Invalid ASCII in A-label")
+ if uts46:
+ s = uts46_remap(s, std3_rules, False)
+- # See encode() for rationale; the same bound applies because every
+- # legal A-domain is at most 254 octets and every codepoint of a
+- # legal U-domain contributes at least one octet to its A-form.
+- if len(s) > 254:
++ # Reject inputs that exceed the maximum DNS domain length up-front
++ # to avoid expensive computation on long inputs.
++ if not valid_string_length(s, trailing_dot=True):
+ raise IDNAError("Domain too long")
+ trailing_dot = False
+ result = []
diff --git a/meta/recipes-devtools/python/python3-idna/CVE-2026-45409_p3.patch b/meta/recipes-devtools/python/python3-idna/CVE-2026-45409_p3.patch
new file mode 100644
index 00000000000..f7302a94170
--- /dev/null
+++ b/meta/recipes-devtools/python/python3-idna/CVE-2026-45409_p3.patch
@@ -0,0 +1,72 @@
+From bd119cd4055324ece8a9bb1ef5413e3ad581b0ed Mon Sep 17 00:00:00 2001
+From: metsw24-max <metsw24@gmail.com>
+Date: Mon, 11 May 2026 20:59:30 +0530
+Subject: [PATCH] Enforce early length limits in check_label
+
+CVE: CVE-2026-45409
+Upstream-Status: Backport [https://github.com/kjd/idna/commit/e1cb465b6376f33306a26f467d197edbcd01c4b9]
+
+(cherry picked from commit e1cb465b6376f33306a26f467d197edbcd01c4b9)
+Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
+---
+ idna/core.py | 11 +++++++++++
+ tests/test_idna.py | 24 ++++++++++++++++++++++++
+ 2 files changed, 35 insertions(+)
+
+diff --git a/idna/core.py b/idna/core.py
+index db19bda..254f090 100644
+--- a/idna/core.py
++++ b/idna/core.py
+@@ -247,6 +247,17 @@ def check_label(label: Union[str, bytes, bytearray]) -> None:
+ label = label.decode("utf-8")
+ if len(label) == 0:
+ raise IDNAError("Empty Label")
++ # Reject oversized labels before per-codepoint validation runs.
++ # CONTEXTJ/CONTEXTO checks scan the whole label per codepoint, so an
++ # uncapped label drives validation into quadratic time
++ # (GHSA-65pc-fj4g-8rjx / CVE-2024-3651). encode()/decode() cap the
++ # whole-domain length; this cap protects direct callers of
++ # alabel/ulabel/check_label and the idna2008 incremental codec.
++ # Use the whole-domain bound rather than the per-label DNS bound so
++ # that UTS #46 lenient decoding of labels longer than 63 chars is
++ # preserved.
++ if not valid_string_length(label, trailing_dot=True):
++ raise IDNAError("Label too long")
+
+ check_nfc(label)
+ check_hyphen_ok(label)
+diff --git a/tests/test_idna.py b/tests/test_idna.py
+index ff24ebf..9832c39 100755
+--- a/tests/test_idna.py
++++ b/tests/test_idna.py
+@@ -93,6 +93,30 @@ class IDNATests(unittest.TestCase):
+ self.assertRaises(idna.IDNAError, idna.decode, payload)
+ self.assertLess(time.perf_counter() - start, 1.0)
+
++ def test_oversized_label_rejected_promptly(self):
++ # The whole-domain cap in encode()/decode() does not cover direct
++ # callers of alabel/ulabel/check_label, nor the idna2008
++ # incremental codec which calls alabel/ulabel per label. Without a
++ # per-label cap, a single oversized CONTEXTO-heavy label still
++ # drives validation into quadratic time.
++ import codecs
++ import time
++
++ import idna.codec # noqa: F401 (register the idna2008 codec)
++
++ payload = "・" * 8000 + "漢"
++ start = time.perf_counter()
++ self.assertRaises(idna.IDNAError, idna.check_label, payload)
++ self.assertRaises(idna.IDNAError, idna.alabel, payload)
++ self.assertRaises(idna.IDNAError, idna.ulabel, payload)
++ self.assertRaises(
++ idna.IDNAError,
++ codecs.getincrementalencoder("idna2008")().encode,
++ payload,
++ True,
++ )
++ self.assertLess(time.perf_counter() - start, 1.0)
++
+ def test_check_bidi(self):
+ la = "\u0061"
+ r = "\u05d0"
diff --git a/meta/recipes-devtools/python/python3-idna_3.11.bb b/meta/recipes-devtools/python/python3-idna_3.11.bb
index eb875729345..1a852561a46 100644
--- a/meta/recipes-devtools/python/python3-idna_3.11.bb
+++ b/meta/recipes-devtools/python/python3-idna_3.11.bb
@@ -3,6 +3,10 @@ HOMEPAGE = "https://github.com/kjd/idna"
LICENSE = "BSD-3-Clause & Python-2.0 & Unicode-TOU"
LIC_FILES_CHKSUM = "file://LICENSE.md;md5=18a4795c19833413a7e2f1cb3cd3b143"
+SRC_URI += "file://CVE-2026-45409_p1.patch \
+ file://CVE-2026-45409_p2.patch \
+ file://CVE-2026-45409_p3.patch \
+ "
SRC_URI[sha256sum] = "795dafcc9c04ed0c1fb032c2aa73654d8e8c5023a7df64a53f39190ada629902"
inherit pypi python_flit_core ptest-python-pytest
^ permalink raw reply related [flat|nested] 41+ messages in thread
* [OE-core][wrynose 34/40] perl: fix CVE-2026-42496 and CVE-2026-42497
2026-09-05 20:44 [OE-core][wrynose 00/40] Patch review Yoann Congal
` (32 preceding siblings ...)
2026-09-05 20:44 ` [OE-core][wrynose 33/40] python3-idna: Fix CVE-2026-45409 Yoann Congal
@ 2026-09-05 20:44 ` Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 35/40] libssh2: Fix CVE-2026-58051 Yoann Congal
` (5 subsequent siblings)
39 siblings, 0 replies; 41+ messages in thread
From: Yoann Congal @ 2026-09-05 20:44 UTC (permalink / raw)
To: openembedded-core
From: Abhishek Bachiphale <Abhishek.Bachiphale@windriver.com>
Archive::Tar before 3.08 passes the tar header's linkname directly to
symlink()/link() in _make_special_file() without validating absolute
paths or '..' segments. This allows a crafted tar archive to create
symlinks or hardlinks targeting paths outside the extraction directory,
leading to arbitrary file read/write.
Backport patch to fix CVE-2026-42496 and CVE-2026-42497.
Reference:
[https://nvd.nist.gov/vuln/detail/CVE-2026-42496]
[https://nvd.nist.gov/vuln/detail/CVE-2026-42497]
Upstream Patch:
[https://github.com/jib/archive-tar-new/commit/17c873492a05eddc0de18c1485e0b2cccd5a9158]
Signed-off-by: Abhishek Bachiphale <Abhishek.Bachiphale@windriver.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
[YC: in perl, the fix was integrated with
https://github.com/Perl/perl5/commit/560820ab273deb6b27408c8e5c2f34d72b1c3bbb (v5.43.11) ]
---
.../perl/files/CVE-2026-42496.patch | 99 +++++++++++++++++++
meta/recipes-devtools/perl/perl_5.42.0.bb | 1 +
2 files changed, 100 insertions(+)
create mode 100644 meta/recipes-devtools/perl/files/CVE-2026-42496.patch
diff --git a/meta/recipes-devtools/perl/files/CVE-2026-42496.patch b/meta/recipes-devtools/perl/files/CVE-2026-42496.patch
new file mode 100644
index 00000000000..ae370340cf5
--- /dev/null
+++ b/meta/recipes-devtools/perl/files/CVE-2026-42496.patch
@@ -0,0 +1,99 @@
+From edde2083c6e93e42b979068af5529710b5e2a7ab Mon Sep 17 00:00:00 2001
+From: Stig Palmquist <stig@stig.io>
+Date: Thu, 21 May 2026 19:59:21 +0100
+Subject: [PATCH] Validate symlink and hardlink linkname in SECURE MODE
+
+Archive::Tar before 3.08 passes the tar header's linkname directly to
+symlink()/link() in _make_special_file() without validating absolute
+paths or '..' segments. This allows a crafted tar archive to create
+symlinks or hardlinks targeting paths outside the extraction directory,
+leading to arbitrary file read/write.
+
+Add validation in SECURE EXTRACT MODE (the default) to reject:
+- Symlink/hardlink targets with absolute paths
+- Symlink/hardlink targets containing '..' path traversal
+
+Adjusted patch paths from upstream Archive::Tar standalone repository
+(lib/Archive/Tar.pm) to match perl5 source tree layout
+(cpan/Archive-Tar/lib/Archive/Tar.pm).
+
+Upstream-Status: Backport [https://github.com/jib/archive-tar-new/commit/17c873492a05eddc0de18c1485e0b2cccd5a9158]
+
+CVE: CVE-2026-42496
+CVE: CVE-2026-42497
+
+Signed-off-by: Chris 'BinGOs' Williams <chris@bingosnet.co.uk>
+Signed-off-by: Abhishek Bachiphale <Abhishek.Bachiphale@windriver.com>
+---
+ cpan/Archive-Tar/lib/Archive/Tar.pm | 30 +++++++++++++++++++++++++
+ cpan/Archive-Tar/t/04_resolved_issues.t | 2 ++
+ 2 files changed, 32 insertions(+)
+
+diff --git a/cpan/Archive-Tar/lib/Archive/Tar.pm b/cpan/Archive-Tar/lib/Archive/Tar.pm
+index 2df0931..733feef 100644
+--- a/cpan/Archive-Tar/lib/Archive/Tar.pm
++++ b/cpan/Archive-Tar/lib/Archive/Tar.pm
+@@ -954,6 +954,19 @@ sub _make_special_file {
+ my $err;
+
+ if( $entry->is_symlink ) {
++ if( !$INSECURE_EXTRACT_MODE ) {
++ my $linkname = $entry->linkname;
++ if( File::Spec->file_name_is_absolute($linkname) ) {
++ $self->_error( qq[Symlink '] . $entry->full_path .
++ qq[' has absolute target. Not extracting under SECURE EXTRACT MODE] );
++ return;
++ }
++ if( grep { $_ eq '..' } File::Spec->splitdir($linkname) ) {
++ $self->_error( qq[Symlink '] . $entry->full_path .
++ qq[' target attempts traversal. Not extracting under SECURE EXTRACT MODE] );
++ return;
++ }
++ }
+ my $fail;
+ if( ON_UNIX ) {
+ symlink( $entry->linkname, $file ) or $fail++;
+@@ -967,6 +980,23 @@ sub _make_special_file {
+ $entry->linkname .q[' failed] if $fail;
+
+ } elsif ( $entry->is_hardlink ) {
++ if( !$INSECURE_EXTRACT_MODE ) {
++ my $linkname = $entry->linkname;
++ if( File::Spec->file_name_is_absolute($linkname) ) {
++ $self->_error( qq[Hardlink '] . $entry->full_path .
++ qq[' has absolute target '$linkname'. Not extracting ] .
++ qq[under SECURE EXTRACT MODE: extraction itself chmods ] .
++ qq[the shared inode.] );
++ return;
++ }
++ if( grep { $_ eq '..' } File::Spec->splitdir($linkname) ) {
++ $self->_error( qq[Hardlink '] . $entry->full_path .
++ qq[' target '$linkname' attempts traversal. Not ] .
++ qq[extracting under SECURE EXTRACT MODE: extraction ] .
++ qq[itself chmods the shared inode.] );
++ return;
++ }
++ }
+ my $fail;
+ if( ON_UNIX ) {
+ link( $entry->linkname, $file ) or $fail++;
+diff --git a/cpan/Archive-Tar/t/04_resolved_issues.t b/cpan/Archive-Tar/t/04_resolved_issues.t
+index b3566a1..08d339a 100644
+--- a/cpan/Archive-Tar/t/04_resolved_issues.t
++++ b/cpan/Archive-Tar/t/04_resolved_issues.t
+@@ -220,6 +220,7 @@ if ($^O ne 'msys') # symlink tests fail on Windows/msys2
+ }
+
+ { #use case 1 - in memory extraction
++ local $Archive::Tar::INSECURE_EXTRACT_MODE=1;
+ my $t=Archive::Tar->new;
+ $t->read( $archname );
+ my $r = eval{ $t->extract };
+@@ -231,6 +232,7 @@ if ($^O ne 'msys') # symlink tests fail on Windows/msys2
+
+ { #use case 2 - iter extraction
+ #$DB::single = 2;
++ local $Archive::Tar::INSECURE_EXTRACT_MODE=1;
+ my $next=Archive::Tar->iter( $archname, 1 );
+ my $failed = 0;
+ #use Data::Dumper;
diff --git a/meta/recipes-devtools/perl/perl_5.42.0.bb b/meta/recipes-devtools/perl/perl_5.42.0.bb
index 8716f1f2572..3469258f727 100644
--- a/meta/recipes-devtools/perl/perl_5.42.0.bb
+++ b/meta/recipes-devtools/perl/perl_5.42.0.bb
@@ -21,6 +21,7 @@ SRC_URI = "https://www.cpan.org/src/5.0/perl-${PV}.tar.gz;name=perl \
file://CVE-2026-13221.patch \
file://CVE-2026-57432-01.patch \
file://CVE-2026-57432-02.patch \
+ file://CVE-2026-42496.patch \
"
SRC_URI:append:class-native = " \
file://perl-configpm-switch.patch \
^ permalink raw reply related [flat|nested] 41+ messages in thread
* [OE-core][wrynose 35/40] libssh2: Fix CVE-2026-58051
2026-09-05 20:44 [OE-core][wrynose 00/40] Patch review Yoann Congal
` (33 preceding siblings ...)
2026-09-05 20:44 ` [OE-core][wrynose 34/40] perl: fix CVE-2026-42496 and CVE-2026-42497 Yoann Congal
@ 2026-09-05 20:44 ` Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 36/40] python3-cryptography: backport stray file install fix Yoann Congal
` (4 subsequent siblings)
39 siblings, 0 replies; 41+ messages in thread
From: Yoann Congal @ 2026-09-05 20:44 UTC (permalink / raw)
To: openembedded-core
From: Hetvi Thakar <hthakar@cisco.com>
Backport the upstream fix for CVE-2026-58051 using the
commit in [1].
The CVE advisory [2] describes an uninitialized
publickey-list entry cleanup issue affecting libssh2
through 1.11.1.
[1] https://github.com/libssh2/libssh2/commit/a9758da45a52bc8c630ec9493804d0c6ea30b24a
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-58051
Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../libssh2/libssh2/CVE-2026-58051.patch | 34 +++++++++++++++++++
.../recipes-support/libssh2/libssh2_1.11.1.bb | 1 +
2 files changed, 35 insertions(+)
create mode 100644 meta/recipes-support/libssh2/libssh2/CVE-2026-58051.patch
diff --git a/meta/recipes-support/libssh2/libssh2/CVE-2026-58051.patch b/meta/recipes-support/libssh2/libssh2/CVE-2026-58051.patch
new file mode 100644
index 00000000000..68f71efe68e
--- /dev/null
+++ b/meta/recipes-support/libssh2/libssh2/CVE-2026-58051.patch
@@ -0,0 +1,34 @@
+From 8cb6cf1244e8d62175bf5df32a400f00ddadb40d Mon Sep 17 00:00:00 2001
+From: Viktor Szakats <vszakats@users.noreply.github.com>
+Date: Mon, 29 Jun 2026 19:12:21 +0200
+Subject: [PATCH] publickey: fix potential arbitrary free in
+ `libssh2_publickey_list_fetch()` (#2127)
+
+Due to uninitialized list entry.
+
+Reported-and-patch-by: Behzod Abdullayev
+Reported-by: Sharique Raza
+
+Follow-up to e15f5d97a04cc676ce117dd324fef85b046207a9
+
+CVE: CVE-2026-58051
+Upstream-Status: Backport [https://github.com/libssh2/libssh2/commit/a9758da45a52bc8c630ec9493804d0c6ea30b24a]
+
+(cherry picked from commit a9758da45a52bc8c630ec9493804d0c6ea30b24a)
+Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
+---
+ src/publickey.c | 1 +
+ 1 file changed, 1 insertion(+)
+
+diff --git a/src/publickey.c b/src/publickey.c
+index 9c9fa618..87bc894f 100644
+--- a/src/publickey.c
++++ b/src/publickey.c
+@@ -972,6 +972,7 @@ libssh2_publickey_list_fetch(LIBSSH2_PUBLICKEY * pkey, unsigned long *num_keys,
+ goto err_exit;
+ }
+ list = newlist;
++ memset(&list[keys], 0, sizeof(list[keys]));
+ }
+ if(pkey->version == 1) {
+ unsigned long comment_len;
diff --git a/meta/recipes-support/libssh2/libssh2_1.11.1.bb b/meta/recipes-support/libssh2/libssh2_1.11.1.bb
index 52684ae74ef..3c72f844adf 100644
--- a/meta/recipes-support/libssh2/libssh2_1.11.1.bb
+++ b/meta/recipes-support/libssh2/libssh2_1.11.1.bb
@@ -21,6 +21,7 @@ SRC_URI = "http://www.libssh2.org/download/${BP}.tar.gz \
file://CVE-2026-66034.patch \
file://CVE-2026-66035.patch \
file://CVE-2026-58050.patch \
+ file://CVE-2026-58051.patch \
"
SRC_URI[sha256sum] = "d9ec76cbe34db98eec3539fe2c899d26b0c837cb3eb466a56b0f109cabf658f7"
^ permalink raw reply related [flat|nested] 41+ messages in thread
* [OE-core][wrynose 36/40] python3-cryptography: backport stray file install fix
2026-09-05 20:44 [OE-core][wrynose 00/40] Patch review Yoann Congal
` (34 preceding siblings ...)
2026-09-05 20:44 ` [OE-core][wrynose 35/40] libssh2: Fix CVE-2026-58051 Yoann Congal
@ 2026-09-05 20:44 ` Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 37/40] qemu: guard RESOLVE_CACHED strace flag Yoann Congal
` (3 subsequent siblings)
39 siblings, 0 replies; 41+ messages in thread
From: Yoann Congal @ 2026-09-05 20:44 UTC (permalink / raw)
To: openembedded-core
From: Deepak Rathore <deeratho@cisco.com>
Maturin 1.12 changed the handling of include entries from
pyproject.toml. With the current cryptography metadata, files like
CHANGELOG.rst, CONTRIBUTING.rst, docs and tests can be installed under
site-packages instead of being kept only in the source archive.
That can cause image install conflicts when packages such as
python3-pyrad and python3-pyexpect are installed with
python3-cryptography, because those packages also install top-level docs
or tests directories under site-packages.
Backport the upstream cryptography fix which marks these entries as
sdist-only. The files remain available from the source tree, so the
existing ptest install path which copies tests from ${S} is not changed.
Signed-off-by: Deepak Rathore <deeratho@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../python/python3-cryptography.bb | 1 +
...lling-stray-files-into-site-packages.patch | 55 +++++++++++++++++++
2 files changed, 56 insertions(+)
create mode 100644 meta/recipes-devtools/python/python3-cryptography/0002-Fix-installing-stray-files-into-site-packages.patch
diff --git a/meta/recipes-devtools/python/python3-cryptography.bb b/meta/recipes-devtools/python/python3-cryptography.bb
index 7f9bde15d03..c6561deb3c4 100644
--- a/meta/recipes-devtools/python/python3-cryptography.bb
+++ b/meta/recipes-devtools/python/python3-cryptography.bb
@@ -14,6 +14,7 @@ require python3-cryptography-common.inc
SRC_URI[sha256sum] = "e4cfd68c5f3e0bfdad0d38e023239b96a2fe84146481852dffbcca442c245aa5"
SRC_URI += "file://0001-pyproject.toml-remove-benchmark-disable-option.patch \
+ file://0002-Fix-installing-stray-files-into-site-packages.patch \
file://check-memfree.py \
file://run-ptest \
"
diff --git a/meta/recipes-devtools/python/python3-cryptography/0002-Fix-installing-stray-files-into-site-packages.patch b/meta/recipes-devtools/python/python3-cryptography/0002-Fix-installing-stray-files-into-site-packages.patch
new file mode 100644
index 00000000000..a04861f1868
--- /dev/null
+++ b/meta/recipes-devtools/python/python3-cryptography/0002-Fix-installing-stray-files-into-site-packages.patch
@@ -0,0 +1,55 @@
+From af53f00da0538e7d64625eea9f4ec850a2b7dd2e Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?Micha=C5=82=20G=C3=B3rny?= <mgorny@gentoo.org>
+Date: Sun, 15 Feb 2026 18:01:37 +0100
+Subject: [PATCH] Fix installing stray files into site-packages (#14319)
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
+
+Fix the `include` pattern in `pyproject.toml` not to install stray files
+such as `CHANGELOG.rst`, `CONTRIBUTING.rst`, `docs` and `tests` straight
+into site-packages. Apparently Maturin did not install them before due
+to a bug, but it was fixed in maturin 1.12.0, leading to the files being
+suddenly installed.
+
+Originally reported as https://bugs.gentoo.org/970090.
+
+Upstream-Status: Backport [https://github.com/pyca/cryptography/commit/43eb178ee3aae8d0060221118437b03c23570a41]
+
+Signed-off-by: Michał Górny <mgorny@gentoo.org>
+(cherry picked from commit 43eb178ee3aae8d0060221118437b03c23570a41)
+Signed-off-by: Deepak Rathore <deeratho@cisco.com>
+---
+ pyproject.toml | 8 ++++----
+ 1 file changed, 4 insertions(+), 4 deletions(-)
+
+diff --git a/pyproject.toml b/pyproject.toml
+index 75bfcbb94..8ee43d17a 100644
+--- a/pyproject.toml
++++ b/pyproject.toml
+@@ -106,10 +106,10 @@ module-name = "cryptography.hazmat.bindings._rust"
+ locked = true
+ sdist-generator = "git"
+ include = [
+- "CHANGELOG.rst",
+- "CONTRIBUTING.rst",
++ { path = "CHANGELOG.rst", format = "sdist" },
++ { path = "CONTRIBUTING.rst", format = "sdist" },
+
+- "docs/**/*",
++ { path = "docs/**/*", format = "sdist" },
+
+ { path = "src/_cffi_src/**/*.py", format = "sdist" },
+ { path = "src/_cffi_src/**/*.c", format = "sdist" },
+@@ -121,7 +121,7 @@ include = [
+ { path = "src/rust/**/Cargo.lock", format = "sdist" },
+ { path = "src/rust/**/*.rs", format = "sdist" },
+
+- "tests/**/*.py",
++ { path = "tests/**/*.py", format = "sdist" },
+ ]
+ exclude = [
+ "vectors/**/*",
+--
+2.35.6
+
^ permalink raw reply related [flat|nested] 41+ messages in thread
* [OE-core][wrynose 37/40] qemu: guard RESOLVE_CACHED strace flag
2026-09-05 20:44 [OE-core][wrynose 00/40] Patch review Yoann Congal
` (35 preceding siblings ...)
2026-09-05 20:44 ` [OE-core][wrynose 36/40] python3-cryptography: backport stray file install fix Yoann Congal
@ 2026-09-05 20:44 ` Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 38/40] util-linux: set status for CVE-2026-13595 Yoann Congal
` (2 subsequent siblings)
39 siblings, 0 replies; 41+ messages in thread
From: Yoann Congal @ 2026-09-05 20:44 UTC (permalink / raw)
To: openembedded-core
From: Deepak Rathore <deeratho@cisco.com>
qemu-native build can fail on build hosts which have an older
linux/openat2.h header. The header is new enough to enable
HAVE_OPENAT2_H, but it does not have RESOLVE_CACHED because that flag
was added later in kernel 5.12.
In that case linux-user/strace.c tries to use RESOLVE_CACHED and build
fails with:
error: 'RESOLVE_CACHED' undeclared here
This is mainly seen with qemu-native because it is built for the host
and can pick the host kernel UAPI header. The buildtools header may have
RESOLVE_CACHED, but native build still has to be safe with older host
headers also.
Add the upstream QEMU fix which checks RESOLVE_CACHED before using it.
This does not change anything on newer hosts. On older hosts QEMU just
does not print this one strace flag because the local header does not
know about it.
Signed-off-by: Deepak Rathore <deeratho@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
meta/recipes-devtools/qemu/qemu.inc | 1 +
...-if-RESOLVE_CACHED-flag-is-defined-b.patch | 38 +++++++++++++++++++
2 files changed, 39 insertions(+)
create mode 100644 meta/recipes-devtools/qemu/qemu/0012-linux-user-Check-if-RESOLVE_CACHED-flag-is-defined-b.patch
diff --git a/meta/recipes-devtools/qemu/qemu.inc b/meta/recipes-devtools/qemu/qemu.inc
index 60a5c62fe9f..cc8f2ecdfad 100644
--- a/meta/recipes-devtools/qemu/qemu.inc
+++ b/meta/recipes-devtools/qemu/qemu.inc
@@ -41,6 +41,7 @@ SRC_URI = "https://download.qemu.org/${BPN}-${PV}.tar.xz \
file://CVE-2026-0665.patch \
file://CVE-2025-14876_p1.patch \
file://CVE-2025-14876_p2.patch \
+ file://0012-linux-user-Check-if-RESOLVE_CACHED-flag-is-defined-b.patch \
"
# file index at download.qemu.org isn't reliable: https://gitlab.com/qemu-project/qemu-web/-/issues/9
UPSTREAM_CHECK_URI = "https://www.qemu.org"
diff --git a/meta/recipes-devtools/qemu/qemu/0012-linux-user-Check-if-RESOLVE_CACHED-flag-is-defined-b.patch b/meta/recipes-devtools/qemu/qemu/0012-linux-user-Check-if-RESOLVE_CACHED-flag-is-defined-b.patch
new file mode 100644
index 00000000000..f23557dc9b9
--- /dev/null
+++ b/meta/recipes-devtools/qemu/qemu/0012-linux-user-Check-if-RESOLVE_CACHED-flag-is-defined-b.patch
@@ -0,0 +1,38 @@
+From 09e077b87eed754cc0aac0f54d193d49f978c93f Mon Sep 17 00:00:00 2001
+From: Frank Chang <frank.chang@sifive.com>
+Date: Thu, 12 Feb 2026 17:54:49 +0800
+Subject: [PATCH] linux-user: Check if RESOLVE_CACHED flag is defined before
+ using it
+
+Upstream-Status: Backport [https://gitlab.com/qemu-project/qemu/-/commit/7ac4bded6af90a15a9562515743a789236b062d1]
+
+openat2.h was introduced in Linux kernel 5.6. However, RESOLVE_CACHED
+flag was only added in kernel 5.12 and later. Therefore, we need to check
+if RESOLVE_CACHED flag is defined before using it.
+
+Signed-off-by: Frank Chang <frank.chang@sifive.com>
+Reviewed-by: Helge Deller <deller@gmx.de>
+Signed-off-by: Helge Deller <deller@gmx.de>
+(cherry picked from commit 7ac4bded6af90a15a9562515743a789236b062d1)
+Signed-off-by: Deepak Rathore <deeratho@cisco.com>
+---
+ linux-user/strace.c | 2 ++
+ 1 file changed, 2 insertions(+)
+
+diff --git a/linux-user/strace.c b/linux-user/strace.c
+index 758c5d32b6..a903b414fd 100644
+--- a/linux-user/strace.c
++++ b/linux-user/strace.c
+@@ -1125,7 +1125,9 @@ UNUSED static const struct flags openat2_resolve_flags[] = {
+ FLAG_GENERIC(RESOLVE_NO_SYMLINKS),
+ FLAG_GENERIC(RESOLVE_BENEATH),
+ FLAG_GENERIC(RESOLVE_IN_ROOT),
++#ifdef RESOLVE_CACHED
+ FLAG_GENERIC(RESOLVE_CACHED),
++#endif
+ #endif
+ FLAG_END,
+ };
+--
+2.35.6
+
^ permalink raw reply related [flat|nested] 41+ messages in thread
* [OE-core][wrynose 38/40] util-linux: set status for CVE-2026-13595
2026-09-05 20:44 [OE-core][wrynose 00/40] Patch review Yoann Congal
` (36 preceding siblings ...)
2026-09-05 20:44 ` [OE-core][wrynose 37/40] qemu: guard RESOLVE_CACHED strace flag Yoann Congal
@ 2026-09-05 20:44 ` Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 39/40] go: upgrade 1.26.6 -> 1.26.7 Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 40/40] scripts/install-buildtools: Update to 6.0.3 Yoann Congal
39 siblings, 0 replies; 41+ messages in thread
From: Yoann Congal @ 2026-09-05 20:44 UTC (permalink / raw)
To: openembedded-core
From: Peter Marko <peter.marko@siemens.com>
Per [1] this bas backported to 2.41.5.
[1] https://security-tracker.debian.org/tracker/CVE-2026-13595
Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
[YC:
Fixed the inequality in the comment, commit message and [1]
tell ">= 2.41.5".
]
---
meta/recipes-core/util-linux/util-linux.inc | 2 ++
1 file changed, 2 insertions(+)
diff --git a/meta/recipes-core/util-linux/util-linux.inc b/meta/recipes-core/util-linux/util-linux.inc
index fdc62acc748..09916594b0a 100644
--- a/meta/recipes-core/util-linux/util-linux.inc
+++ b/meta/recipes-core/util-linux/util-linux.inc
@@ -26,3 +26,5 @@ SRC_URI = "${KERNELORG_MIRROR}/linux/utils/util-linux/v${MAJOR_VERSION}/util-lin
SRC_URI[sha256sum] = "f586e35d320ff537aab3ffeca37e9ecd482ccbe013590db4429a414d8aa6a728"
CVE_PRODUCT = "util-linux"
+
+CVE_STATUS[CVE-2026-13595] = "cpe-stable-backport: Fixed from version >=2.41.5"
^ permalink raw reply related [flat|nested] 41+ messages in thread
* [OE-core][wrynose 39/40] go: upgrade 1.26.6 -> 1.26.7
2026-09-05 20:44 [OE-core][wrynose 00/40] Patch review Yoann Congal
` (37 preceding siblings ...)
2026-09-05 20:44 ` [OE-core][wrynose 38/40] util-linux: set status for CVE-2026-13595 Yoann Congal
@ 2026-09-05 20:44 ` Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 40/40] scripts/install-buildtools: Update to 6.0.3 Yoann Congal
39 siblings, 0 replies; 41+ messages in thread
From: Yoann Congal @ 2026-09-05 20:44 UTC (permalink / raw)
To: openembedded-core
From: Peter Marko <peter.marko@siemens.com>
Upgrade to latest 1.26.x release [1]:
$ git --no-pager log --oneline go1.26.6..go1.26.7
e3336a22ad (tag: go1.26.7) [release-branch.go1.26] go1.26.7
50e5b59e9c [release-branch.go1.26] net/http: clear ReadHeaderTimeout after accepting an unencrypted h2 conn
98e6631a5a [release-branch.go1.26] cmd/internal/moddeps: restore tests
This minor release includes a fix to address a breakage affecting
unencrypted HTTP/2 (h2c) connections caused by a security patch
included in last week’s release. See go.dev/issue/80876 for details.
Release information: [2]
[1] https://github.com/golang/go/compare/go1.26.6...go1.26.7
[2] https://groups.google.com/g/golang-announce/c/qA6Vpj2UA-4
Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(From OE-Core rev: e6739374b865cae8d6f105c7a600a52736579c25)
Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
meta/recipes-devtools/go/{go-1.26.6.inc => go-1.26.7.inc} | 2 +-
...o-binary-native_1.26.6.bb => go-binary-native_1.26.7.bb} | 6 +++---
...cross-canadian_1.26.6.bb => go-cross-canadian_1.26.7.bb} | 0
.../go/{go-cross_1.26.6.bb => go-cross_1.26.7.bb} | 0
.../go/{go-crosssdk_1.26.6.bb => go-crosssdk_1.26.7.bb} | 0
.../go/{go-runtime_1.26.6.bb => go-runtime_1.26.7.bb} | 0
meta/recipes-devtools/go/{go_1.26.6.bb => go_1.26.7.bb} | 0
7 files changed, 4 insertions(+), 4 deletions(-)
rename meta/recipes-devtools/go/{go-1.26.6.inc => go-1.26.7.inc} (90%)
rename meta/recipes-devtools/go/{go-binary-native_1.26.6.bb => go-binary-native_1.26.7.bb} (80%)
rename meta/recipes-devtools/go/{go-cross-canadian_1.26.6.bb => go-cross-canadian_1.26.7.bb} (100%)
rename meta/recipes-devtools/go/{go-cross_1.26.6.bb => go-cross_1.26.7.bb} (100%)
rename meta/recipes-devtools/go/{go-crosssdk_1.26.6.bb => go-crosssdk_1.26.7.bb} (100%)
rename meta/recipes-devtools/go/{go-runtime_1.26.6.bb => go-runtime_1.26.7.bb} (100%)
rename meta/recipes-devtools/go/{go_1.26.6.bb => go_1.26.7.bb} (100%)
diff --git a/meta/recipes-devtools/go/go-1.26.6.inc b/meta/recipes-devtools/go/go-1.26.7.inc
similarity index 90%
rename from meta/recipes-devtools/go/go-1.26.6.inc
rename to meta/recipes-devtools/go/go-1.26.7.inc
index fa6b0a50a14..fed87015b2c 100644
--- a/meta/recipes-devtools/go/go-1.26.6.inc
+++ b/meta/recipes-devtools/go/go-1.26.7.inc
@@ -16,4 +16,4 @@ SRC_URI += "\
file://0009-go-Filter-build-paths-on-staticly-linked-arches.patch \
file://0010-cmd-go-clear-GOROOT-for-func-ldShared-when-trimpath-.patch \
"
-SRC_URI[main.sha256sum] = "a0721c54c688901448d77ad9b3ec7ea7c474730755ff891382e92ecb93ff2cb1"
+SRC_URI[main.sha256sum] = "0ed24eac755105085b89fe9cabc2742b91a0ad7b94b59d3ad364918ebc8956ad"
diff --git a/meta/recipes-devtools/go/go-binary-native_1.26.6.bb b/meta/recipes-devtools/go/go-binary-native_1.26.7.bb
similarity index 80%
rename from meta/recipes-devtools/go/go-binary-native_1.26.6.bb
rename to meta/recipes-devtools/go/go-binary-native_1.26.7.bb
index 2913fb65151..753f1b13bb5 100644
--- a/meta/recipes-devtools/go/go-binary-native_1.26.6.bb
+++ b/meta/recipes-devtools/go/go-binary-native_1.26.7.bb
@@ -9,9 +9,9 @@ PROVIDES = "go-native"
# Checksums available at https://go.dev/dl/
SRC_URI = "https://dl.google.com/go/go${PV}.${BUILD_GOOS}-${BUILD_GOARCH}.tar.gz;name=go_${BUILD_GOTUPLE}"
-SRC_URI[go_linux_amd64.sha256sum] = "708effb774be8237570d0add163225abbdfaf4fca28b2611df167beba4feef89"
-SRC_URI[go_linux_arm64.sha256sum] = "d0507e9e9d7fe012aae570108cbd76c15de879e17130ab8cb90d4d7445cb1f2e"
-SRC_URI[go_linux_ppc64le.sha256sum] = "232b65543a42eda95df6a63f76235c1795bb535eba5c74e509faec71bc648388"
+SRC_URI[go_linux_amd64.sha256sum] = "ffb5f8de10c62550dfddab66b36b57030721e0a44a3218e9e1181d7b59f121ca"
+SRC_URI[go_linux_arm64.sha256sum] = "5a4ec883379d51ee9ce1040d5e87f8d35e20387574dd8c947feb01eabc3c1b37"
+SRC_URI[go_linux_ppc64le.sha256sum] = "22d3b362d557175fd16b79651cab0cad64f8aaaedca745f66d16f44d56bc5de1"
UPSTREAM_CHECK_URI = "https://golang.org/dl/"
UPSTREAM_CHECK_REGEX = "go(?P<pver>\d+(\.\d+)+)\.linux"
diff --git a/meta/recipes-devtools/go/go-cross-canadian_1.26.6.bb b/meta/recipes-devtools/go/go-cross-canadian_1.26.7.bb
similarity index 100%
rename from meta/recipes-devtools/go/go-cross-canadian_1.26.6.bb
rename to meta/recipes-devtools/go/go-cross-canadian_1.26.7.bb
diff --git a/meta/recipes-devtools/go/go-cross_1.26.6.bb b/meta/recipes-devtools/go/go-cross_1.26.7.bb
similarity index 100%
rename from meta/recipes-devtools/go/go-cross_1.26.6.bb
rename to meta/recipes-devtools/go/go-cross_1.26.7.bb
diff --git a/meta/recipes-devtools/go/go-crosssdk_1.26.6.bb b/meta/recipes-devtools/go/go-crosssdk_1.26.7.bb
similarity index 100%
rename from meta/recipes-devtools/go/go-crosssdk_1.26.6.bb
rename to meta/recipes-devtools/go/go-crosssdk_1.26.7.bb
diff --git a/meta/recipes-devtools/go/go-runtime_1.26.6.bb b/meta/recipes-devtools/go/go-runtime_1.26.7.bb
similarity index 100%
rename from meta/recipes-devtools/go/go-runtime_1.26.6.bb
rename to meta/recipes-devtools/go/go-runtime_1.26.7.bb
diff --git a/meta/recipes-devtools/go/go_1.26.6.bb b/meta/recipes-devtools/go/go_1.26.7.bb
similarity index 100%
rename from meta/recipes-devtools/go/go_1.26.6.bb
rename to meta/recipes-devtools/go/go_1.26.7.bb
^ permalink raw reply related [flat|nested] 41+ messages in thread
* [OE-core][wrynose 40/40] scripts/install-buildtools: Update to 6.0.3
2026-09-05 20:44 [OE-core][wrynose 00/40] Patch review Yoann Congal
` (38 preceding siblings ...)
2026-09-05 20:44 ` [OE-core][wrynose 39/40] go: upgrade 1.26.6 -> 1.26.7 Yoann Congal
@ 2026-09-05 20:44 ` Yoann Congal
39 siblings, 0 replies; 41+ messages in thread
From: Yoann Congal @ 2026-09-05 20:44 UTC (permalink / raw)
To: openembedded-core
From: Yoann Congal <yoann.congal@smile.fr>
Update to the 6.0.3 release of the 6.0 series for buildtools
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
scripts/install-buildtools | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/scripts/install-buildtools b/scripts/install-buildtools
index b59cfbb8705..e1af05fca33 100755
--- a/scripts/install-buildtools
+++ b/scripts/install-buildtools
@@ -57,8 +57,8 @@ logger = scriptutils.logger_create(PROGNAME, stream=sys.stdout)
DEFAULT_INSTALL_DIR = os.path.join(os.path.split(scripts_path)[0],'buildtools')
DEFAULT_BASE_URL = 'https://downloads.yoctoproject.org/releases/yocto'
-DEFAULT_RELEASE = 'yocto-6.0.2'
-DEFAULT_INSTALLER_VERSION = '6.0.2'
+DEFAULT_RELEASE = 'yocto-6.0.3'
+DEFAULT_INSTALLER_VERSION = '6.0.3'
DEFAULT_BUILDDATE = '202110XX'
# Python version sanity check
^ permalink raw reply related [flat|nested] 41+ messages in thread
end of thread, other threads:[~2026-09-05 20:45 UTC | newest]
Thread overview: 41+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-05 20:44 [OE-core][wrynose 00/40] Patch review Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 01/40] apt: mark CVE-2011-3374 as fixed-version Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 02/40] expat: set CVE_STATUS for CVE-2026-72522 Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 03/40] python3-git: fix CVE-2026-42284 Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 04/40] python3-git: fix CVE-2026-42215 Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 05/40] python3-git: fix CVE-2026-44243 Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 06/40] python3-git: fix CVE-2026-44244 Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 07/40] python3-babel: fix CVE_PRODUCT Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 08/40] python3-pycryptodome: " Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 09/40] python3-dbusmock: " Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 10/40] python3-wheel: " Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 11/40] python3-click: " Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 12/40] python3-attrs: " Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 13/40] python3-numpy: " Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 14/40] python3-pycryptodomex: " Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 15/40] python3-mako: upgrade 1.3.10 -> 1.3.12 Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 16/40] gnutls: fix for CVE-2026-42011 Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 17/40] gnutls: fix CVE-2026-42010 Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 18/40] alsa-lib: patch CVE-2026-56109 Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 19/40] libevent: upgrade 2.1.12 -> 2.1.13 Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 20/40] libevent: set status for CVE-2026-63380 Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 21/40] libxfont2: Fix CVE-2026-56001 Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 22/40] libxfont2: Fix CVE-2026-56002 Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 23/40] libxfont2: Fix CVE-2026-56003 Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 24/40] util-linux: Fix CVE-2026-3184 Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 25/40] python3: upgrade 3.14.6 -> 3.14.7 Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 26/40] volatile-binds: order systemd-timesyncd after /var/lib Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 27/40] go: upgrade 1.26.5 -> 1.26.6 Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 28/40] python3: add missing pyc files to core Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 29/40] python3: fix stringold cache files Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 30/40] python3-git: fix CVE_PRODUCT Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 31/40] binutils: stable 2.46 branch updates Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 32/40] python3-click: upgrade 8.3.1 -> 8.3.3 Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 33/40] python3-idna: Fix CVE-2026-45409 Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 34/40] perl: fix CVE-2026-42496 and CVE-2026-42497 Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 35/40] libssh2: Fix CVE-2026-58051 Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 36/40] python3-cryptography: backport stray file install fix Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 37/40] qemu: guard RESOLVE_CACHED strace flag Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 38/40] util-linux: set status for CVE-2026-13595 Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 39/40] go: upgrade 1.26.6 -> 1.26.7 Yoann Congal
2026-09-05 20:44 ` [OE-core][wrynose 40/40] scripts/install-buildtools: Update to 6.0.3 Yoann Congal
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox